CVE-2024-36113

Discourse is an open-source discussion platform. Prior to version 3.2.3 on the `stable` branch, version 3.3.0.beta3 on the `beta` branch, and version 3.3.0.beta4-dev on the `tests-passed` branch, a rogue staff user could suspend other staff users preventing them from logging in to the site. The issue is patched in version 3.2.3 on the `stable` branch, version 3.3.0.beta3 on the `beta` branch, and version 3.3.0.beta4-dev on the `tests-passed` branch. No known workarounds are available.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:discourse:discourse:*:*:*:*:stable:*:*:*
cpe:2.3:a:discourse:discourse:*:*:*:*:beta:*:*:*
cpe:2.3:a:discourse:discourse:3.3.0:beta1:*:*:beta:*:*:*
cpe:2.3:a:discourse:discourse:3.3.0:beta2:*:*:beta:*:*:*

History

18 Sep 2024, 14:44

Type Values Removed Values Added
First Time Discourse
Discourse discourse
CVSS v2 : unknown
v3 : 4.9
v2 : unknown
v3 : 6.5
CPE cpe:2.3:a:discourse:discourse:*:*:*:*:stable:*:*:*
cpe:2.3:a:discourse:discourse:*:*:*:*:beta:*:*:*
cpe:2.3:a:discourse:discourse:3.3.0:beta2:*:*:beta:*:*:*
cpe:2.3:a:discourse:discourse:3.3.0:beta1:*:*:beta:*:*:*
References () https://github.com/discourse/discourse/commit/8470546f59b04bd82ce9b711406758fd5439936d - () https://github.com/discourse/discourse/commit/8470546f59b04bd82ce9b711406758fd5439936d - Patch
References () https://github.com/discourse/discourse/commit/9c4a5f39d3ad351410a1453ff5e5f7ffce17cd7e - () https://github.com/discourse/discourse/commit/9c4a5f39d3ad351410a1453ff5e5f7ffce17cd7e - Patch
References () https://github.com/discourse/discourse/security/advisories/GHSA-3w3f-76p7-3c4g - () https://github.com/discourse/discourse/security/advisories/GHSA-3w3f-76p7-3c4g - Third Party Advisory

05 Jul 2024, 12:55

Type Values Removed Values Added
Summary
  • (es) Discourse es una plataforma de discusión de código abierto. Antes de la versión 3.2.3 en la rama `stable`, la versión 3.3.0.beta3 en la rama `beta` y la versión 3.3.0.beta4-dev en la rama `tests-passed`, un usuario del personal deshonesto podía suspender otros usuarios del personal les impiden iniciar sesión en el sitio. El problema se solucionó en la versión 3.2.3 en la rama `stable`, en la versión 3.3.0.beta3 en la rama `beta` y en la versión 3.3.0.beta4-dev en la rama `tests-passed`. No hay workarounds disponibles.

03 Jul 2024, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-03 19:15

Updated : 2024-09-18 14:44


NVD link : CVE-2024-36113

Mitre link : CVE-2024-36113

CVE.ORG link : CVE-2024-36113


JSON object : View

Products Affected

discourse

  • discourse
CWE
CWE-862

Missing Authorization