Discourse is a platform for community discussion. Users who receive an invitation link that is not scoped to a single email address can enter any non-admin user's email and gain access to their account when accepting the invitation. All users should upgrade to the latest version. A workaround is temporarily disabling invitations with SiteSetting.max_invites_per_day = 0 or scope them to individual email addresses.
| Software | From | Fixed in |
|---|---|---|
| discourse / discourse | 2.9.0-beta1 | 2.9.0-beta1.x |
| discourse / discourse | 2.9.0-beta2 | 2.9.0-beta2.x |
| discourse / discourse | 2.9.0-beta3 | 2.9.0-beta3.x |
| discourse / discourse | 2.9.0-beta4 | 2.9.0-beta4.x |
| discourse / discourse | 2.9.0-beta5 | 2.9.0-beta5.x |
| discourse / discourse | 2.9.0-beta7 | 2.9.0-beta7.x |
| discourse / discourse | 2.9.0-beta8 | 2.9.0-beta8.x |
| discourse / discourse | 2.9.0-beta6 | 2.9.0-beta6.x |
| discourse / discourse | 2.9.0-beta9 | 2.9.0-beta9.x |
| discourse / discourse | 2.9.0-beta10 | 2.9.0-beta10.x |
| discourse / discourse | - | 2.8.10 |