ZeroHour

CVE-2024-49765

CVSS 3.1
9.1 critical
EPSS
<1%p29
Published
()
Modified
Description

Discourse is an open source platform for community discussion. Sites that are using discourse connect but still have local logins enabled could allow attackers to bypass discourse connect to create accounts and login. This problem is patched in the latest version of Discourse. Users unable to upgrade who are using discourse connect may disable all other login methods as a workaround.

Vendors
discourse
Products
discourse
Weakness
CWE-359
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.