CVE-2021-37693
Summary
| CVE | CVE-2021-37693 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-08-13 16:15:00 UTC |
| Updated | 2021-08-30 18:01:00 UTC |
| Description | Discourse is an open-source platform for community discussion. In Discourse before versions 2.7.8 and 2.8.0.beta4, when adding additional email addresses to an existing account on a Discourse site an email token is generated as part of the email verification process. Deleting the additional email address does not invalidate an unused token which can then be used in other contexts, including reseting a password. |
Risk And Classification
Problem Types: CWE-640 | CWE-613
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Re-use of email tokens · Advisory · discourse/discourse · GitHub | CONFIRM | github.com | |
| SECURITY: Destroy `EmailToken` when `EmailChangeRequest` is destroyed… · discourse/discourse@fb14e50 · GitHub | MISC | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.