5
CVSSv2

CVE-2021-3138

Published: 14/01/2021 Updated: 04/01/2022
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 446
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

In Discourse 2.7.0 through beta1, a rate-limit bypass leads to a bypass of the 2FA requirement for certain forms.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

discourse discourse

discourse discourse 2.7.0

Exploits

Discourse version 270 suffers from a 2FA bypass via a rate limiting bypass vulnerability ...

Github Repositories

Discource POC

| Discourse 270 - CVE-2021-3138 | Description : Rate limit Bypass which leads to 2FA Bypass Tested Version : 270 Attack Type: Remote Impact : 2FA Bypass Vendor of Product : wwwdiscourseorg Additional Information : Discourse is discussion platform built for the next decade of the Internet Used as: -mailing list -discussion forum -long-form chat roo

Discource POC

| Discourse 270 - CVE-2021-3138 | Description : Rate limit Bypass which leads to 2FA Bypass Tested Version : 270 Attack Type: Remote Impact : 2FA Bypass Vendor of Product : wwwdiscourseorg Additional Information : Discourse is discussion platform built for the next decade of the Internet Used as: -mailing list -discussion forum -long-form chat roo

Discource POC

| Discourse 270 - CVE-2021-3138 | Description : Rate limit Bypass which leads to 2FA Bypass Tested Version : 270 Attack Type: Remote Impact : 2FA Bypass Vendor of Product : wwwdiscourseorg Additional Information : Discourse is discussion platform built for the next decade of the Internet Used as: -mailing list -discussion forum -long-form chat roo