CVE Vulnerabilities

CVE-2021-43793

Improper Privilege Management

Published: Dec 01, 2021 | Modified: Nov 21, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Discourse is an open source discussion platform. In affected versions a vulnerability in the Polls feature allowed users to vote multiple times in a single-option poll. The problem is patched in the latest tests-passed, beta and stable versions of Discourse

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

NameVendorStart VersionEnd Version
DiscourseDiscourse*2.7.11 (excluding)
DiscourseDiscourse2.8.0-beta1 (including)2.8.0-beta1 (including)
DiscourseDiscourse2.8.0-beta2 (including)2.8.0-beta2 (including)
DiscourseDiscourse2.8.0-beta3 (including)2.8.0-beta3 (including)
DiscourseDiscourse2.8.0-beta4 (including)2.8.0-beta4 (including)
DiscourseDiscourse2.8.0-beta5 (including)2.8.0-beta5 (including)
DiscourseDiscourse2.8.0-beta6 (including)2.8.0-beta6 (including)
DiscourseDiscourse2.8.0-beta7 (including)2.8.0-beta7 (including)

Potential Mitigations

References