# 3.0.4: Beveiligings- en bugfix-release

**URL:** https://meta.discourse.org/t/3-0-4-security-and-bug-fix-release/268185
**Category:** Announcements
**Tags:** release-notes
**Created:** [13 juni 2023 om 18:37 UTC](https://meta.discourse.org/t/3-0-4-security-and-bug-fix-release/268185 "2023-06-13T18:37:15Z")
**Posts on this page:** 1
**Page:** 1

<div class="post-metadata">

### Author: ![jomaxro](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/jomaxro/32/126216_2.png) [@jomaxro](https://meta.discourse.org/u/jomaxro)
#### Post date: [13 juni 2023 om 18:37 UTC](https://meta.discourse.org/t/3-0-4-security-and-bug-fix-release/268185/1 "2023-06-13T18:37:15Z")

</div>

## Discourse 3.0.4 Stable Release

Discourse strongly recommends that all sites follow the default tests-passed branch of Discourse. The “stable” branch is more focused on _lack of change_ than _lack of bugs_ - all releases, including those on tests-passed and beta are production ready.

### Changes

#### Bug Fixes

- Remove obsolete references to lounge category

#### Security Changes

- Do not overwrite permissions on the General category [CVE-2023-31142](https://github.com/discourse/discourse/security/advisories/GHSA-286w-97m2-78x2)
- Prevent dismissal of topics that user can’t see [CVE-2023-34250](https://github.com/discourse/discourse/security/advisories/GHSA-q8m5-wmjr-3ppg)
- set max-height property for iframes [CVE-2023-32061](https://github.com/discourse/discourse/security/advisories/GHSA-prx4-49m8-874g)
- Use canonical url for topic embeddings [CVE-2023-32301](https://github.com/discourse/discourse/security/advisories/GHSA-p2jx-m2j5-hqh4)
