Discourse is an open source discussion platform. Prior to version 3.0.6 of the `stable` branch and version 3.1.0.beta7 of the `beta` and `tests-passed` branches, more users than permitted could be created from invite links. The issue is patched in version 3.0.6 of the `stable` branch and version 3.1.0.beta7 of the `beta` and `tests-passed` branches. As a workaround, use restrict to email address invites.
Attack Vector Network
Attack Complexity High
Privileges Required None
Scope Unchanged
Confidentiality Impact None
Integrity Impact Low
Availability Impact None
User Interaction Required
No CVSS v3.0
No CVSS v2
Vendors | Products |
---|---|
Discourse |
|
Configuration 1 [-]
|
References
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: GitHub_M
Published: 2023-07-28T15:09:08.049Z
Updated: 2023-07-28T15:09:08.049Z
Reserved: 2023-07-10T17:51:29.610Z
Link: CVE-2023-37904
JSON object: View
NVD Information
Status : Analyzed
Published: 2023-07-28T16:15:11.617
Modified: 2023-08-03T17:51:20.897
Link: CVE-2023-37904
JSON object: View
Redhat Information
No data.
CWE