CVE-2021-37693
Re-use of email tokens in Discourse
7.5
HIGH
CVSS 3.1
EPSS 0.32%
Description
Discourse is an open-source platform for community discussion. In Discourse before versions 2.7.8 and 2.8.0.beta4, when adding additional email addresses to an existing account on a Discourse site an email token is generated as part of the email verification process. Deleting the additional email address does not invalidate an unused token which can then be used in other contexts, including reseting a password.
How to fix CVE-2021-37693
To remediate CVE-2021-37693, upgrade the affected package to a fixed version below.
- —upgrade to 2.7.8 or later
Is CVE-2021-37693 being exploited?
Low — EPSS is 0.3%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 2.7.8
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |