CVE 8.2 HIGH

Discourse’s WebAuthn challenge isn’t cleared from user session after authentication_CVE-2025-53102

8.2 / 10
HIGH
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

Description

Discourse is an open-source community discussion platform. Prior to version 3.4.7 on the `stable` branch and version 3.5.0.beta.8 on the `tests-passed` branch, upon issuing a physical security key for 2FA, the server generates a WebAuthn challenge, which the client signs. The challenge is not cleared from the user’s session after authentication, potentially allowing reuse and increasing security risk. This is fixed in versions 3.4.7 and 3.5.0.beta.8.

Basic Information

ID CVE-2025-53102
Source GitHub_M
Published Jul 29, 2025 at 19:24
Modified Jul 29, 2025 at 19:33

Affected Product

Vendor discourse
Product discourse
Version >= 3.5.0.beta1, < 3.5.0.beta.8
Affected Versions discourse discourse >= 3.5.0.beta1, < 3.5.0.beta.8
discourse discourse < 3.4.7

CWE Classification

References

πŸ’­ Join the Security Discussion

πŸ”’ Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.