CVE Vulnerabilities

CVE-2021-43793

Improper Privilege Management

Published: Dec 01, 2021 | Modified: Nov 21, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

Discourse is an open source discussion platform. In affected versions a vulnerability in the Polls feature allowed users to vote multiple times in a single-option poll. The problem is patched in the latest tests-passed, beta and stable versions of Discourse

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

Name Vendor Start Version End Version
Discourse Discourse * 2.7.11 (excluding)
Discourse Discourse 2.8.0-beta1 (including) 2.8.0-beta1 (including)
Discourse Discourse 2.8.0-beta2 (including) 2.8.0-beta2 (including)
Discourse Discourse 2.8.0-beta3 (including) 2.8.0-beta3 (including)
Discourse Discourse 2.8.0-beta4 (including) 2.8.0-beta4 (including)
Discourse Discourse 2.8.0-beta5 (including) 2.8.0-beta5 (including)
Discourse Discourse 2.8.0-beta6 (including) 2.8.0-beta6 (including)
Discourse Discourse 2.8.0-beta7 (including) 2.8.0-beta7 (including)

Potential Mitigations

References