RULE(RULE ID:333509)

Rule General Information
Release Date: 2021-04-28
Rule Name: Discourse 2.7.0 Rate-limit Bypass Vulnerability (CVE-2021-3138)
Severity:
CVE ID:
Rule Protection Details
Description: In Discourse 2.7.0 through beta1, a rate-limit bypass leads to a bypass of the 2FA requirement for certain forms.
Impact: An attacker could exploit this vulnerability to have unspecified effect.
Affected OS: Windows, Linux, Others
Reference: http://packetstormsecurity.com/files/162256/Discourse-2.7.0-2FA-Bypass.html
https://github.com/Mesh3l911/Disource
https://github.com/discourse/discourse/releases
Solutions
The vendor has released upgrade patches to fix vulnerabilities, please visit:
https://github.com/Mesh3l911/Disource