CVE-2019-1020018
on github
Published
Severity
CVSS v3:
7.3 HIGH
CVSS v2:
7.5 HIGH
Description
Discourse before 2.3.0 and 2.4.x before 2.4.0.beta3 lacks a confirmation screen when logging in via an email link.
References
Configurations
CPE23 | Version Start | Version End | Exact Version |
---|---|---|---|
cpe:2.3:a:discourse:discourse:*:*:*:*:*:*:*:* | n/a | 2.3.0 | * |
cpe:2.3:a:discourse:discourse:2.4.0:beta2:*:*:*:*:*:* | n/a | n/a | 2.4.0 |
cpe:2.3:a:discourse:discourse:2.4.0:beta1:*:*:*:*:*:* | n/a | n/a | 2.4.0 |