# 3.2.3: Security and bug fix release

**URL:** https://meta.discourse.org/t/3-2-3-security-and-bug-fix-release/313392
**Category:** Announcements
**Tags:** release-notes
**Created:** [July 3, 2024, 1:14pm UTC](https://meta.discourse.org/t/3-2-3-security-and-bug-fix-release/313392 "2024-07-03T13:14:29Z")
**Posts on this page:** 1
**Page:** 1

<div class="post-metadata">

### Author: ![Saif](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/saif/32/318253_2.png) [@Saif](https://meta.discourse.org/u/Saif)
#### Post date: [July 3, 2024, 1:14pm UTC](https://meta.discourse.org/t/3-2-3-security-and-bug-fix-release/313392/1 "2024-07-03T13:14:29Z")

</div>

## Discourse 3.2.3 Stable Release

Discourse strongly recommends that all sites follow the default tests-passed branch of Discourse. The “stable” branch is more focused on _lack of change_ than _lack of bugs_ - all releases, including those on tests-passed and beta are production ready.

## Security Updates

This release includes fixes for these security issues reported by our community and [HackerOne](https://hackerone.com/discourse).

- DoS through Onebox ([CVE-2024-35227](https://github.com/discourse/discourse/security/advisories/GHSA-664f-xwjw-752c))
- Stored-dom XSS via Facebook Oneboxes ([CVE-2024-35234](https://github.com/discourse/discourse/security/advisories/GHSA-5chg-hm8c-wc58))
- Missing authorization checks for suspending admins/moderators ([CVE-2024-36113](https://github.com/discourse/discourse/security/advisories/GHSA-3w3f-76p7-3c4g))
- Limit reviewable user serializer payload ([CVE-2024-36122](https://github.com/discourse/discourse/security/advisories/GHSA-rr93-hcw4-cv3f))
- SSRF via FastImage ([CVE-2024-37157](https://github.com/discourse/discourse/security/advisories/GHSA-46pq-7958-fc68))
