PT-2023-26173 · Discourse · Discourse

Jomaxro

·

Publicado

2023-07-28

·

Atualizado

2024-03-06

·

CVE-2023-37904

CVSS v3.1

2.6

Baixa

VetorAV:N/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Discourse versions prior to 3.0.6 of the stable branch Discourse versions prior to 3.1.0.beta7 of the beta and tests-passed branches
Description Discourse is an open source discussion platform. The issue allows more users than permitted to be created from invite links. As a workaround, use restrict to email address invites.
Recommendations For versions prior to 3.0.6 of the stable branch, update to version 3.0.6 or later. For versions prior to 3.1.0.beta7 of the beta and tests-passed branches, update to version 3.1.0.beta7 or later. As a temporary workaround, consider restricting invite links to email address invites until a patch is available.

Exploit

Correção

Race Condition

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BIT-DISCOURSE-2023-37904
CVE-2023-37904
GHSA-6WJ5-4PH2-C7QG

Produtos afetados

Discourse