8.2
/ 10
HIGH
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Description
Discourse is an open-source community discussion platform. Prior to version 3.4.7 on the `stable` branch and version 3.5.0.beta.8 on the `tests-passed` branch, upon issuing a physical security key for 2FA, the server generates a WebAuthn challenge, which the client signs. The challenge is not cleared from the userβs session after authentication, potentially allowing reuse and increasing security risk. This is fixed in versions 3.4.7 and 3.5.0.beta.8.
Basic Information
ID
CVE-2025-53102
Source
GitHub_M
Published
Jul 29, 2025 at 19:24
Modified
Jul 29, 2025 at 19:33
Affected Product
Vendor
discourse
Product
discourse
Version
>= 3.5.0.beta1, < 3.5.0.beta.8
Affected Versions
discourse discourse >= 3.5.0.beta1, < 3.5.0.beta.8
discourse discourse < 3.4.7
discourse discourse < 3.4.7