CVE-2021-3138: High severity Discourse Discourse vulnerability
Published Jan 14, 2021
·Updated
In Discourse 2.7.0 through beta1, a rate-limit bypass leads to a bypass of the 2FA requirement for certain forms.
Affected Software
2 affected components
Discourse Discourse<=2.6.0
Discourse Discourse=2.7.0-beta1
Event History
Jan 14, 2021
CVE Published
via MITRE·03:30 AM
Data Sourced
via MITRE·03:30 AM
Description
Data Sourced
via NVD·04:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2021-3138?
CVE-2021-3138 has a medium severity rating as it allows a rate-limit bypass leading to a circumvention of the two-factor authentication requirement.
2
How do I fix CVE-2021-3138?
To fix CVE-2021-3138, upgrade Discourse to version 2.7.0 or later beyond the beta1 release.
3
Which versions of Discourse are affected by CVE-2021-3138?
CVE-2021-3138 affects Discourse versions 2.7.0-beta1 and all earlier versions up to 2.6.0.
4
What impact does CVE-2021-3138 have on user security?
The impact of CVE-2021-3138 allows attackers to bypass two-factor authentication, potentially compromising user accounts.
5
Is there a workaround for CVE-2021-3138 before upgrading?
There is no official workaround for CVE-2021-3138; upgrading to a patched version is recommended for protection.