First published: Mon Jul 29 2019(Updated: )
Discourse before 2.3.0 and 2.4.x before 2.4.0.beta3 lacks a confirmation screen when logging in via a user-api OTP.
Credit: josh@bress.net
Affected Software | Affected Version | How to fix |
---|---|---|
Discourse Discourse | <2.3.0 | |
Discourse Discourse | =2.4.0-beta1 | |
Discourse Discourse | =2.4.0-beta2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2019-1020017.
The severity of CVE-2019-1020017 is medium.
Discourse versions before 2.3.0 and 2.4.x before 2.4.0.beta3 are affected by CVE-2019-1020017.
CVE-2019-1020017 allows an attacker to log in via a user-api OTP without a confirmation screen.
To fix CVE-2019-1020017, upgrade Discourse to version 2.3.0 or higher.