# 3.1.3: Security and bug fix release

**URL:** https://meta.discourse.org/t/3-1-3-security-and-bug-fix-release/284973
**Category:** Announcements
**Tags:** release-notes
**Created:** [November 9, 2023, 5:21pm UTC](https://meta.discourse.org/t/3-1-3-security-and-bug-fix-release/284973 "2023-11-09T17:21:14Z")
**Posts on this page:** 1
**Page:** 1

<div class="post-metadata">

### Author: ![jomaxro](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/jomaxro/32/126216_2.png) [@jomaxro](https://meta.discourse.org/u/jomaxro)
#### Post date: [November 9, 2023, 5:21pm UTC](https://meta.discourse.org/t/3-1-3-security-and-bug-fix-release/284973/1 "2023-11-09T17:21:14Z")

</div>

## Discourse 3.1.3 Stable Release

Discourse strongly recommends that all sites follow the default tests-passed branch of Discourse. The “stable” branch is more focused on _lack of change_ than _lack of bugs_ - all releases, including those on tests-passed and beta are production ready.

### Security Changes

- Prevent Onebox cache overflow by limiting downloads and URL lengths [CVE-2023-47120](https://github.com/discourse/discourse/security/advisories/GHSA-77cw-xhj8-hfp3)
- Filter unread bookmark reminders the user cannot see [CVE-2023-45816](https://github.com/discourse/discourse/security/advisories/GHSA-v9r6-92wp-f6cf)
- Limit height of pre/svg elements [CVE-2023-46130](https://github.com/discourse/discourse/security/advisories/GHSA-c876-638r-vfcg)
- Onebox templates’ HTML injections. [CVE-2023-47119](https://github.com/discourse/discourse/security/advisories/GHSA-j95w-5hvx-jp5w)
- SSRF vulnerability in TopicEmbed [CVE-2023-47121](https://github.com/discourse/discourse/security/advisories/GHSA-hp24-94qf-8cgc)
- Escape display names [CVE-2023-45806](https://github.com/discourse/discourse/security/advisories/GHSA-hcgf-hg2g-mw78)
