CVE-2021-3138

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
14/01/2021
Last modified:
04/01/2022

Description

In Discourse 2.7.0 through beta1, a rate-limit bypass leads to a bypass of the 2FA requirement for certain forms.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:discourse:discourse:*:*:*:*:*:*:*:* 2.6.0 (including)
cpe:2.3:a:discourse:discourse:2.7.0:beta1:*:*:*:*:*:*