CVE-2021-37693
Re-use of email tokens in Discourse
7.5
HIGH
CVSS 3.1
EPSS 0.83%
描述
Discourse is an open-source platform for community discussion. In Discourse before versions 2.7.8 and 2.8.0.beta4, when adding additional email addresses to an existing account on a Discourse site an email token is generated as part of the email verification process. Deleting the additional email address does not invalidate an unused token which can then be used in other contexts, including reseting a password.
如何修補 CVE-2021-37693
要修補 CVE-2021-37693,請將受影響套件升級到下列已修補版本。
- —升級至 2.7.8 或更新版本
CVE-2021-37693 正在被利用嗎?
低 — EPSS 為 0.8%,目前沒有觀察到大規模利用活動。
受影響套件(1)
- from 0, < 2.7.8
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |