CVE-2021-37693
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
13/08/2021
Last modified:
30/08/2021
Description
Discourse is an open-source platform for community discussion. In Discourse before versions 2.7.8 and 2.8.0.beta4, when adding additional email addresses to an existing account on a Discourse site an email token is generated as part of the email verification process. Deleting the additional email address does not invalidate an unused token which can then be used in other contexts, including reseting a password.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
Base Score 2.0
5.00
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:discourse:discourse:*:*:*:*:*:*:*:* | 2.7.8 (excluding) | |
| cpe:2.3:a:discourse:discourse:2.8.0:beta1:*:*:*:*:*:* | ||
| cpe:2.3:a:discourse:discourse:2.8.0:beta2:*:*:*:*:*:* | ||
| cpe:2.3:a:discourse:discourse:2.8.0:beta3:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



