PT-2024-26900 · Discourse · Discourse

Nattsw

·

Published

2024-07-03

·

Updated

2024-09-18

·

CVE-2024-36113

CVSS v3.1

4.9

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Discourse versions prior to 3.2.3 Discourse versions prior to 3.3.0.beta3 Discourse versions prior to 3.3.0.beta4-dev
Description A rogue staff user could suspend other staff users, preventing them from logging in to the site.
Recommendations For versions prior to 3.2.3, update to version 3.2.3 or later. For versions prior to 3.3.0.beta3, update to version 3.3.0.beta3 or later. For versions prior to 3.3.0.beta4-dev, update to version 3.3.0.beta4-dev or later.

Exploit

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

BIT-DISCOURSE-2024-36113
CVE-2024-36113
GHSA-3W3F-76P7-3C4G

Affected Products

Discourse