PT-2023-26173 · Discourse · Discourse

Jomaxro

·

Published

2023-07-28

·

Updated

2024-03-06

·

CVE-2023-37904

CVSS v3.1

2.6

Low

VectorAV:N/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Discourse versions prior to 3.0.6 of the stable branch Discourse versions prior to 3.1.0.beta7 of the beta and tests-passed branches
Description Discourse is an open source discussion platform. The issue allows more users than permitted to be created from invite links. As a workaround, use restrict to email address invites.
Recommendations For versions prior to 3.0.6 of the stable branch, update to version 3.0.6 or later. For versions prior to 3.1.0.beta7 of the beta and tests-passed branches, update to version 3.1.0.beta7 or later. As a temporary workaround, consider restricting invite links to email address invites until a patch is available.

Exploit

Fix

Race Condition

Weakness Enumeration

Related Identifiers

BIT-DISCOURSE-2023-37904
CVE-2023-37904
GHSA-6WJ5-4PH2-C7QG

Affected Products

Discourse