First published: Thu Jan 14 2021(Updated: )
In Discourse 2.7.0 through beta1, a rate-limit bypass leads to a bypass of the 2FA requirement for certain forms.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Discourse Discourse | <=2.6.0 | |
Discourse Discourse | =2.7.0-beta1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.