PT-2024-31403 · Discourse · Discourse

Nattsw

·

Published

2024-10-07

·

Updated

2025-09-25

·

CVE-2024-45051

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Discourse versions prior to the latest stable, beta and tests-passed version
Description A maliciously crafted email address could allow an attacker to bypass domain-based restrictions and gain access to private sites, categories, and/or groups. This issue has been patched in the latest stable, beta, and tests-passed version of Discourse. There are no known workarounds for this issue.
Recommendations Upgrade to the latest stable, beta, or tests-passed version of Discourse to mitigate the risk of exploitation. As a temporary workaround, consider restricting access to private sites, categories, and/or groups until the upgrade is complete. Avoid using encoded email addresses in the affected Discourse email handler until the issue is resolved.

Exploit

Fix

Improper Authentication

Weakness Enumeration

Related Identifiers

BIT-DISCOURSE-2024-45051
CVE-2024-45051
GHSA-2VJV-PGH4-6RMQ

Affected Products

Discourse