CVE-2021-3138
14.01.2021, 04:15
In Discourse 2.7.0 through beta1, a rate-limit bypass leads to a bypass of the 2FA requirement for certain forms.Enginsight
| Vendor | Product | Version |
|---|---|---|
| discourse | discourse | 𝑥 ≤ 2.6.0 |
| discourse | discourse | 2.7.0:beta1 |
𝑥
= Vulnerable software versions
References