Aller au contenu

Fiche vulnérabilité

CVE-2021-37693 : faille élevée discourse discourse (CVSS 7.5)

Description

Discourse is an open-source platform for community discussion. In Discourse before versions 2.7.8 and 2.8.0.beta4, when adding additional email addresses to an existing account on a Discourse site an email token is generated as part of the email verification process. Deleting the additional email address does not invalidate an unused token which can then be used in other contexts, including reseting a password.

En bref

Sévérité
Élevée (CVSS 7.5)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Exploitation active
Non signalée par la CISA
Publication
13 août 2021
Dernière mise à jour
17 juin 2026

Produits concernés

  • discourse discourse

Références

Rechercher une autre vulnérabilité dans la base CVE