CVE-2024-49765
Discourse is an open source platform for community discussion. Sites that are using discourse connect but still have local logins enabled could allow attackers to bypass discourse connect to create accounts and login. This problem is patched in the latest version of Discourse. Users unable to upgrade who are using discourse connect may disable all other login methods as a workaround.
- Affected products
- Discourse
- Discourse
- < 3.3.3, 3.4.0
- Fix
- Available
- CVSS 3.1
- 9.1 CRITICAL
- EPSS
- 0.4% (29th percentile)
- Weakness
- CWE-359
- NVD status
- Analyzed
- Published
- 2024-12-19
CVE-2024-49765 at NVD
No indexed exploits for CVE-2024-49765 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2024-49765 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.