CVE-2023-37904

LOW3.1EPSS 0.18%

Discourse Race Condition in Accept Invite

發布日:2024/3/6修改日:2025/10/15
也稱為:GHSA-6wj5-4ph2-c7qgBIT-discourse-2023-37904

描述

Discourse is an open source discussion platform. Prior to version 3.0.6 of the `stable` branch and version 3.1.0.beta7 of the `beta` and `tests-passed` branches, more users than permitted could be created from invite links. The issue is patched in version 3.0.6 of the `stable` branch and version 3.1.0.beta7 of the `beta` and `tests-passed` branches. As a workaround, use restrict to email address invites.

受影響套件(1)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1LOW3.1CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N

參考連結(3)