CVE-2022-31184
01.08.2022, 20:15
Discourse is the an open source discussion platform. In affected versions an email activation route can be abused to send mass spam emails. A fix has been included in the latest stable, beta and tests-passed versions of Discourse which rate limits emails. Users are advised to upgrade. Users unable to upgrade should manually rate limit email.Enginsight
Vendor | Product | Version |
---|---|---|
discourse | discourse | 𝑥 ≤ 2.8.6 |
discourse | discourse | 2.9.0:beta1 |
discourse | discourse | 2.9.0:beta2 |
discourse | discourse | 2.9.0:beta3 |
discourse | discourse | 2.9.0:beta4 |
discourse | discourse | 2.9.0:beta5 |
discourse | discourse | 2.9.0:beta6 |
discourse | discourse | 2.9.0:beta7 |
𝑥
= Vulnerable software versions
References