CVE Vulnerabilities

CVE-2023-36466

Improper Authentication

Published: Jul 14, 2023 | Modified: Jul 27, 2023
CVSS 3.x
4.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Discourse is an open source discussion platform. When editing a topic, there is a vulnerability that enables a user to bypass the topic title validations for things like title length, number of emojis in title and blank topic titles. The issue is patched in the latest stable, beta and tests-passed version of Discourse.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Discourse Discourse * 3.0.5 (excluding)
Discourse Discourse 1.1.0-beta1 (including) 1.1.0-beta1 (including)
Discourse Discourse 1.1.0-beta2 (including) 1.1.0-beta2 (including)
Discourse Discourse 1.1.0-beta3 (including) 1.1.0-beta3 (including)
Discourse Discourse 1.1.0-beta4 (including) 1.1.0-beta4 (including)
Discourse Discourse 1.1.0-beta5 (including) 1.1.0-beta5 (including)
Discourse Discourse 1.1.0-beta6 (including) 1.1.0-beta6 (including)
Discourse Discourse 1.1.0-beta6b (including) 1.1.0-beta6b (including)
Discourse Discourse 1.1.0-beta7 (including) 1.1.0-beta7 (including)
Discourse Discourse 1.1.0-beta8 (including) 1.1.0-beta8 (including)
Discourse Discourse 1.2.0-beta1 (including) 1.2.0-beta1 (including)
Discourse Discourse 1.2.0-beta2 (including) 1.2.0-beta2 (including)
Discourse Discourse 1.2.0-beta3 (including) 1.2.0-beta3 (including)
Discourse Discourse 1.2.0-beta4 (including) 1.2.0-beta4 (including)
Discourse Discourse 1.2.0-beta5 (including) 1.2.0-beta5 (including)
Discourse Discourse 1.2.0-beta6 (including) 1.2.0-beta6 (including)
Discourse Discourse 1.2.0-beta7 (including) 1.2.0-beta7 (including)
Discourse Discourse 1.2.0-beta8 (including) 1.2.0-beta8 (including)
Discourse Discourse 1.2.0-beta9 (including) 1.2.0-beta9 (including)
Discourse Discourse 1.3.0-beta1 (including) 1.3.0-beta1 (including)
Discourse Discourse 1.3.0-beta10 (including) 1.3.0-beta10 (including)
Discourse Discourse 1.3.0-beta11 (including) 1.3.0-beta11 (including)
Discourse Discourse 1.3.0-beta2 (including) 1.3.0-beta2 (including)
Discourse Discourse 1.3.0-beta3 (including) 1.3.0-beta3 (including)
Discourse Discourse 1.3.0-beta4 (including) 1.3.0-beta4 (including)
Discourse Discourse 1.3.0-beta5 (including) 1.3.0-beta5 (including)
Discourse Discourse 1.3.0-beta6 (including) 1.3.0-beta6 (including)
Discourse Discourse 1.3.0-beta7 (including) 1.3.0-beta7 (including)
Discourse Discourse 1.3.0-beta8 (including) 1.3.0-beta8 (including)
Discourse Discourse 1.3.0-beta9 (including) 1.3.0-beta9 (including)
Discourse Discourse 1.4.0-beta1 (including) 1.4.0-beta1 (including)
Discourse Discourse 1.4.0-beta10 (including) 1.4.0-beta10 (including)
Discourse Discourse 1.4.0-beta11 (including) 1.4.0-beta11 (including)
Discourse Discourse 1.4.0-beta12 (including) 1.4.0-beta12 (including)
Discourse Discourse 1.4.0-beta2 (including) 1.4.0-beta2 (including)
Discourse Discourse 1.4.0-beta3 (including) 1.4.0-beta3 (including)
Discourse Discourse 1.4.0-beta4 (including) 1.4.0-beta4 (including)
Discourse Discourse 1.4.0-beta5 (including) 1.4.0-beta5 (including)
Discourse Discourse 1.4.0-beta6 (including) 1.4.0-beta6 (including)
Discourse Discourse 1.4.0-beta7 (including) 1.4.0-beta7 (including)
Discourse Discourse 1.4.0-beta8 (including) 1.4.0-beta8 (including)
Discourse Discourse 1.4.0-beta9 (including) 1.4.0-beta9 (including)
Discourse Discourse 1.5.0-beta1 (including) 1.5.0-beta1 (including)
Discourse Discourse 1.5.0-beta10 (including) 1.5.0-beta10 (including)
Discourse Discourse 1.5.0-beta11 (including) 1.5.0-beta11 (including)
Discourse Discourse 1.5.0-beta12 (including) 1.5.0-beta12 (including)
Discourse Discourse 1.5.0-beta13 (including) 1.5.0-beta13 (including)
Discourse Discourse 1.5.0-beta13b (including) 1.5.0-beta13b (including)
Discourse Discourse 1.5.0-beta14 (including) 1.5.0-beta14 (including)
Discourse Discourse 1.5.0-beta2 (including) 1.5.0-beta2 (including)
Discourse Discourse 1.5.0-beta3 (including) 1.5.0-beta3 (including)
Discourse Discourse 1.5.0-beta4 (including) 1.5.0-beta4 (including)
Discourse Discourse 1.5.0-beta5 (including) 1.5.0-beta5 (including)
Discourse Discourse 1.5.0-beta6 (including) 1.5.0-beta6 (including)
Discourse Discourse 1.5.0-beta7 (including) 1.5.0-beta7 (including)
Discourse Discourse 1.5.0-beta8 (including) 1.5.0-beta8 (including)
Discourse Discourse 1.5.0-beta9 (including) 1.5.0-beta9 (including)
Discourse Discourse 1.6.0-beta1 (including) 1.6.0-beta1 (including)
Discourse Discourse 1.6.0-beta10 (including) 1.6.0-beta10 (including)
Discourse Discourse 1.6.0-beta11 (including) 1.6.0-beta11 (including)
Discourse Discourse 1.6.0-beta12 (including) 1.6.0-beta12 (including)
Discourse Discourse 1.6.0-beta2 (including) 1.6.0-beta2 (including)
Discourse Discourse 1.6.0-beta3 (including) 1.6.0-beta3 (including)
Discourse Discourse 1.6.0-beta4 (including) 1.6.0-beta4 (including)
Discourse Discourse 1.6.0-beta5 (including) 1.6.0-beta5 (including)
Discourse Discourse 1.6.0-beta6 (including) 1.6.0-beta6 (including)
Discourse Discourse 1.6.0-beta7 (including) 1.6.0-beta7 (including)
Discourse Discourse 1.6.0-beta8 (including) 1.6.0-beta8 (including)
Discourse Discourse 1.6.0-beta9 (including) 1.6.0-beta9 (including)
Discourse Discourse 1.7.0-beta1 (including) 1.7.0-beta1 (including)
Discourse Discourse 1.7.0-beta10 (including) 1.7.0-beta10 (including)
Discourse Discourse 1.7.0-beta11 (including) 1.7.0-beta11 (including)
Discourse Discourse 1.7.0-beta2 (including) 1.7.0-beta2 (including)
Discourse Discourse 1.7.0-beta3 (including) 1.7.0-beta3 (including)
Discourse Discourse 1.7.0-beta4 (including) 1.7.0-beta4 (including)
Discourse Discourse 1.7.0-beta5 (including) 1.7.0-beta5 (including)
Discourse Discourse 1.7.0-beta6 (including) 1.7.0-beta6 (including)
Discourse Discourse 1.7.0-beta7 (including) 1.7.0-beta7 (including)
Discourse Discourse 1.7.0-beta8 (including) 1.7.0-beta8 (including)
Discourse Discourse 1.7.0-beta9 (including) 1.7.0-beta9 (including)
Discourse Discourse 1.8.0-beta1 (including) 1.8.0-beta1 (including)
Discourse Discourse 1.8.0-beta10 (including) 1.8.0-beta10 (including)
Discourse Discourse 1.8.0-beta11 (including) 1.8.0-beta11 (including)
Discourse Discourse 1.8.0-beta12 (including) 1.8.0-beta12 (including)
Discourse Discourse 1.8.0-beta13 (including) 1.8.0-beta13 (including)
Discourse Discourse 1.8.0-beta2 (including) 1.8.0-beta2 (including)
Discourse Discourse 1.8.0-beta3 (including) 1.8.0-beta3 (including)
Discourse Discourse 1.8.0-beta4 (including) 1.8.0-beta4 (including)
Discourse Discourse 1.8.0-beta5 (including) 1.8.0-beta5 (including)
Discourse Discourse 1.8.0-beta6 (including) 1.8.0-beta6 (including)
Discourse Discourse 1.8.0-beta7 (including) 1.8.0-beta7 (including)
Discourse Discourse 1.8.0-beta8 (including) 1.8.0-beta8 (including)
Discourse Discourse 1.8.0-beta9 (including) 1.8.0-beta9 (including)
Discourse Discourse 1.9.0-beta1 (including) 1.9.0-beta1 (including)
Discourse Discourse 1.9.0-beta10 (including) 1.9.0-beta10 (including)
Discourse Discourse 1.9.0-beta11 (including) 1.9.0-beta11 (including)
Discourse Discourse 1.9.0-beta12 (including) 1.9.0-beta12 (including)
Discourse Discourse 1.9.0-beta13 (including) 1.9.0-beta13 (including)
Discourse Discourse 1.9.0-beta14 (including) 1.9.0-beta14 (including)
Discourse Discourse 1.9.0-beta15 (including) 1.9.0-beta15 (including)
Discourse Discourse 1.9.0-beta16 (including) 1.9.0-beta16 (including)
Discourse Discourse 1.9.0-beta17 (including) 1.9.0-beta17 (including)
Discourse Discourse 1.9.0-beta2 (including) 1.9.0-beta2 (including)
Discourse Discourse 1.9.0-beta3 (including) 1.9.0-beta3 (including)
Discourse Discourse 1.9.0-beta4 (including) 1.9.0-beta4 (including)
Discourse Discourse 1.9.0-beta5 (including) 1.9.0-beta5 (including)
Discourse Discourse 1.9.0-beta6 (including) 1.9.0-beta6 (including)
Discourse Discourse 1.9.0-beta7 (including) 1.9.0-beta7 (including)
Discourse Discourse 1.9.0-beta8 (including) 1.9.0-beta8 (including)
Discourse Discourse 1.9.0-beta9 (including) 1.9.0-beta9 (including)
Discourse Discourse 2.0.0-beta1 (including) 2.0.0-beta1 (including)
Discourse Discourse 2.0.0-beta10 (including) 2.0.0-beta10 (including)
Discourse Discourse 2.0.0-beta2 (including) 2.0.0-beta2 (including)
Discourse Discourse 2.0.0-beta3 (including) 2.0.0-beta3 (including)
Discourse Discourse 2.0.0-beta4 (including) 2.0.0-beta4 (including)
Discourse Discourse 2.0.0-beta5 (including) 2.0.0-beta5 (including)
Discourse Discourse 2.0.0-beta6 (including) 2.0.0-beta6 (including)
Discourse Discourse 2.0.0-beta7 (including) 2.0.0-beta7 (including)
Discourse Discourse 2.0.0-beta8 (including) 2.0.0-beta8 (including)
Discourse Discourse 2.0.0-beta9 (including) 2.0.0-beta9 (including)
Discourse Discourse 2.1.0-beta1 (including) 2.1.0-beta1 (including)
Discourse Discourse 2.1.0-beta2 (including) 2.1.0-beta2 (including)
Discourse Discourse 2.1.0-beta3 (including) 2.1.0-beta3 (including)
Discourse Discourse 2.1.0-beta4 (including) 2.1.0-beta4 (including)
Discourse Discourse 2.1.0-beta5 (including) 2.1.0-beta5 (including)
Discourse Discourse 2.1.0-beta6 (including) 2.1.0-beta6 (including)
Discourse Discourse 2.2.0-beta1 (including) 2.2.0-beta1 (including)
Discourse Discourse 2.2.0-beta10 (including) 2.2.0-beta10 (including)
Discourse Discourse 2.2.0-beta2 (including) 2.2.0-beta2 (including)
Discourse Discourse 2.2.0-beta3 (including) 2.2.0-beta3 (including)
Discourse Discourse 2.2.0-beta4 (including) 2.2.0-beta4 (including)
Discourse Discourse 2.2.0-beta5 (including) 2.2.0-beta5 (including)
Discourse Discourse 2.2.0-beta6 (including) 2.2.0-beta6 (including)
Discourse Discourse 2.2.0-beta7 (including) 2.2.0-beta7 (including)
Discourse Discourse 2.2.0-beta8 (including) 2.2.0-beta8 (including)
Discourse Discourse 2.2.0-beta9 (including) 2.2.0-beta9 (including)
Discourse Discourse 2.3.0-beta1 (including) 2.3.0-beta1 (including)
Discourse Discourse 2.3.0-beta10 (including) 2.3.0-beta10 (including)
Discourse Discourse 2.3.0-beta11 (including) 2.3.0-beta11 (including)
Discourse Discourse 2.3.0-beta2 (including) 2.3.0-beta2 (including)
Discourse Discourse 2.3.0-beta3 (including) 2.3.0-beta3 (including)
Discourse Discourse 2.3.0-beta4 (including) 2.3.0-beta4 (including)
Discourse Discourse 2.3.0-beta5 (including) 2.3.0-beta5 (including)
Discourse Discourse 2.3.0-beta6 (including) 2.3.0-beta6 (including)
Discourse Discourse 2.3.0-beta7 (including) 2.3.0-beta7 (including)
Discourse Discourse 2.3.0-beta8 (including) 2.3.0-beta8 (including)
Discourse Discourse 2.3.0-beta9 (including) 2.3.0-beta9 (including)
Discourse Discourse 2.4.0-beta1 (including) 2.4.0-beta1 (including)
Discourse Discourse 2.4.0-beta10 (including) 2.4.0-beta10 (including)
Discourse Discourse 2.4.0-beta11 (including) 2.4.0-beta11 (including)
Discourse Discourse 2.4.0-beta2 (including) 2.4.0-beta2 (including)
Discourse Discourse 2.4.0-beta3 (including) 2.4.0-beta3 (including)
Discourse Discourse 2.4.0-beta4 (including) 2.4.0-beta4 (including)
Discourse Discourse 2.4.0-beta5 (including) 2.4.0-beta5 (including)
Discourse Discourse 2.4.0-beta6 (including) 2.4.0-beta6 (including)
Discourse Discourse 2.4.0-beta7 (including) 2.4.0-beta7 (including)
Discourse Discourse 2.4.0-beta8 (including) 2.4.0-beta8 (including)
Discourse Discourse 2.4.0-beta9 (including) 2.4.0-beta9 (including)
Discourse Discourse 2.5.0-beta1 (including) 2.5.0-beta1 (including)
Discourse Discourse 2.5.0-beta2 (including) 2.5.0-beta2 (including)
Discourse Discourse 2.5.0-beta3 (including) 2.5.0-beta3 (including)
Discourse Discourse 2.5.0-beta4 (including) 2.5.0-beta4 (including)
Discourse Discourse 2.5.0-beta5 (including) 2.5.0-beta5 (including)
Discourse Discourse 2.5.0-beta6 (including) 2.5.0-beta6 (including)
Discourse Discourse 2.5.0-beta7 (including) 2.5.0-beta7 (including)
Discourse Discourse 2.6.0-beta1 (including) 2.6.0-beta1 (including)
Discourse Discourse 2.6.0-beta2 (including) 2.6.0-beta2 (including)
Discourse Discourse 2.6.0-beta3 (including) 2.6.0-beta3 (including)
Discourse Discourse 2.6.0-beta4 (including) 2.6.0-beta4 (including)
Discourse Discourse 2.6.0-beta5 (including) 2.6.0-beta5 (including)
Discourse Discourse 2.6.0-beta6 (including) 2.6.0-beta6 (including)
Discourse Discourse 2.7.0-beta1 (including) 2.7.0-beta1 (including)
Discourse Discourse 2.7.0-beta2 (including) 2.7.0-beta2 (including)
Discourse Discourse 2.7.0-beta3 (including) 2.7.0-beta3 (including)
Discourse Discourse 2.7.0-beta4 (including) 2.7.0-beta4 (including)
Discourse Discourse 2.7.0-beta5 (including) 2.7.0-beta5 (including)
Discourse Discourse 2.7.0-beta6 (including) 2.7.0-beta6 (including)
Discourse Discourse 2.7.0-beta7 (including) 2.7.0-beta7 (including)
Discourse Discourse 2.7.0-beta8 (including) 2.7.0-beta8 (including)
Discourse Discourse 2.7.0-beta9 (including) 2.7.0-beta9 (including)
Discourse Discourse 2.8.0-beta1 (including) 2.8.0-beta1 (including)
Discourse Discourse 2.8.0-beta10 (including) 2.8.0-beta10 (including)
Discourse Discourse 2.8.0-beta11 (including) 2.8.0-beta11 (including)
Discourse Discourse 2.8.0-beta2 (including) 2.8.0-beta2 (including)
Discourse Discourse 2.8.0-beta3 (including) 2.8.0-beta3 (including)
Discourse Discourse 2.8.0-beta4 (including) 2.8.0-beta4 (including)
Discourse Discourse 2.8.0-beta5 (including) 2.8.0-beta5 (including)
Discourse Discourse 2.8.0-beta6 (including) 2.8.0-beta6 (including)
Discourse Discourse 2.8.0-beta7 (including) 2.8.0-beta7 (including)
Discourse Discourse 2.8.0-beta8 (including) 2.8.0-beta8 (including)
Discourse Discourse 2.8.0-beta9 (including) 2.8.0-beta9 (including)
Discourse Discourse 2.9.0-beta1 (including) 2.9.0-beta1 (including)
Discourse Discourse 2.9.0-beta10 (including) 2.9.0-beta10 (including)
Discourse Discourse 2.9.0-beta11 (including) 2.9.0-beta11 (including)
Discourse Discourse 2.9.0-beta12 (including) 2.9.0-beta12 (including)
Discourse Discourse 2.9.0-beta13 (including) 2.9.0-beta13 (including)
Discourse Discourse 2.9.0-beta14 (including) 2.9.0-beta14 (including)
Discourse Discourse 2.9.0-beta2 (including) 2.9.0-beta2 (including)
Discourse Discourse 2.9.0-beta3 (including) 2.9.0-beta3 (including)
Discourse Discourse 2.9.0-beta4 (including) 2.9.0-beta4 (including)
Discourse Discourse 2.9.0-beta5 (including) 2.9.0-beta5 (including)
Discourse Discourse 2.9.0-beta6 (including) 2.9.0-beta6 (including)
Discourse Discourse 2.9.0-beta7 (including) 2.9.0-beta7 (including)
Discourse Discourse 2.9.0-beta8 (including) 2.9.0-beta8 (including)
Discourse Discourse 2.9.0-beta9 (including) 2.9.0-beta9 (including)
Discourse Discourse 3.0.0-beta15 (including) 3.0.0-beta15 (including)
Discourse Discourse 3.0.0-beta16 (including) 3.0.0-beta16 (including)
Discourse Discourse 3.1.0-beta1 (including) 3.1.0-beta1 (including)
Discourse Discourse 3.1.0-beta2 (including) 3.1.0-beta2 (including)
Discourse Discourse 3.1.0-beta5 (including) 3.1.0-beta5 (including)

Potential Mitigations

References