Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-53102


Discourse is an open-source community discussion platform. Prior to version 3.4.7 on the `stable` branch and version 3.5.0.beta.8 on the `tests-passed` branch, upon issuing a physical security key for 2FA, the server generates a WebAuthn challenge, which the client signs. The challenge is not cleared from the user’s session after authentication, potentially allowing reuse and increasing security risk. This is fixed in versions 3.4.7 and 3.5.0.beta.8.


Published

2025-07-29T20:15:28.327

Last Modified

2025-08-25T17:47:56.500

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

Weaknesses
  • Type: Secondary
    CWE-384

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application discourse discourse < 3.4.6 Yes
Application discourse discourse ≤ 3.5.0 Yes
Application discourse discourse 3.5.0 Yes
Application discourse discourse 3.5.0 Yes
Application discourse discourse 3.5.0 Yes
Application discourse discourse 3.5.0 Yes
Application discourse discourse 3.5.0 Yes
Application discourse discourse 3.5.0 Yes
Application discourse discourse 3.5.0 Yes

References