Описание
In Discourse 2.7.0 through beta1, a rate-limit bypass leads to a bypass of the 2FA requirement for certain forms.
Ссылки
- ExploitThird Party AdvisoryVDB Entry
- Third Party Advisory
- Release NotesThird Party Advisory
- ExploitThird Party AdvisoryVDB Entry
- Third Party Advisory
- Release NotesThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 2.6.0 (включая)
Одно из
cpe:2.3:a:discourse:discourse:*:*:*:*:*:*:*:*
cpe:2.3:a:discourse:discourse:2.7.0:beta1:*:*:*:*:*:*
EPSS
Процентиль: 85%
0.02655
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-307
Связанные уязвимости
github
больше 3 лет назад
In Discourse 2.7.0 through beta1, a rate-limit bypass leads to a bypass of the 2FA requirement for certain forms.
EPSS
Процентиль: 85%
0.02655
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-307