Vulnerabilities > Discourse > Discourse > 0.9.8.10

DATE CVE VULNERABILITY TITLE RISK
2019-07-29 CVE-2019-1020018 Improper Authentication vulnerability in Discourse
Discourse before 2.3.0 and 2.4.x before 2.4.0.beta3 lacks a confirmation screen when logging in via an email link.
network
low complexity
discourse CWE-287
7.5
2019-07-29 CVE-2019-1020017 Unspecified vulnerability in Discourse
Discourse before 2.3.0 and 2.4.x before 2.4.0.beta3 lacks a confirmation screen when logging in via a user-api OTP.
network
low complexity
discourse
5.3