CVE-2021-3138
In Discourse 2.7.0 through beta1, a rate-limit bypass leads to a bypass of the 2FA requirement for certain forms.
- Affected products
- Discourse
- Discourse
- ≤ 2.6.0, 2.7.0
- CVSS 3.1
- 7.5 HIGH
- EPSS
- 3.1% (87th percentile)
- Weakness
- CWE-307
- NVD status
- Modified
- Published
- 2021-01-14
CVE-2021-3138 at NVD
4 known exploits for CVE-2021-3138
Proof-of-concept code and exploit modules indexed by Sploitus