CVE-2024-45051: Bypass of email address validation via encoded email addresses in Discourse
Discourse is an open source platform for community discussion. A maliciously crafted email address could allow an attacker to bypass domain-based restrictions and gain access to private sites, categories and/or groups. This issue has been patched in the latest stable, beta and tests-passed version of Discourse. All users area are advised to upgrade. There are no known workarounds for this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-45051?
CVE-2024-45051 is considered a critical vulnerability due to its potential to allow unauthorized access to private community discussions.
How do I fix CVE-2024-45051?
To fix CVE-2024-45051, update your Discourse installation to the latest stable version or any version beyond 3.3.2 or 3.4.0.
What is the vulnerability in CVE-2024-45051?
CVE-2024-45051 allows attackers to bypass domain-based restrictions using a crafted email address, potentially gaining access to private sites and groups.
Which versions of Discourse are affected by CVE-2024-45051?
CVE-2024-45051 affects Discourse versions prior to 3.3.2 and versions between 3.4.0-beta1 and 3.4.0 inclusive.
Is there a patch available for CVE-2024-45051?
Yes, a patch for CVE-2024-45051 has been provided in the latest stable release of Discourse.