Discourse is an open source platform for community discussion. A maliciously crafted email address could allow an attacker to bypass domain-based restrictions and gain access to private sites, categories and/or groups. This issue has been patched in the latest stable, beta and tests-passed version of Discourse. All users area are advised to upgrade. There are no known workarounds for this vulnerability.
History

Sat, 19 Oct 2024 01:30:00 +0000

Type Values Removed Values Added
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:discourse:discourse:*:*:*:*:beta:*:*:*
cpe:2.3:a:discourse:discourse:*:*:*:*:stable:*:*:*
cpe:2.3:a:discourse:discourse:3.4.0:-:*:*:beta:*:*:*
cpe:2.3:a:discourse:discourse:3.4.0:beta1:*:*:beta:*:*:*

Tue, 08 Oct 2024 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Discourse
Discourse discourse
CPEs cpe:2.3:a:discourse:discourse:*:*:*:*:*:*:*:*
Vendors & Products Discourse
Discourse discourse
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 07 Oct 2024 20:45:00 +0000

Type Values Removed Values Added
Description Discourse is an open source platform for community discussion. A maliciously crafted email address could allow an attacker to bypass domain-based restrictions and gain access to private sites, categories and/or groups. This issue has been patched in the latest stable, beta and tests-passed version of Discourse. All users area are advised to upgrade. There are no known workarounds for this vulnerability.
Title Bypass of email address validation via encoded email addresses in Discourse
Weaknesses CWE-287
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2024-10-07T20:23:01.955Z

Updated: 2024-10-08T18:26:35.183Z

Reserved: 2024-08-21T17:53:51.331Z

Link: CVE-2024-45051

cve-icon Vulnrichment

Updated: 2024-10-08T18:26:27.746Z

cve-icon NVD

Status : Analyzed

Published: 2024-10-07T21:15:16.930

Modified: 2024-10-19T01:11:16.810

Link: CVE-2024-45051

cve-icon Redhat

No data.