# 3.3.2: Security and maintenance release

**URL:** https://meta.discourse.org/t/3-3-2-security-and-maintenance-release/329341
**Category:** Announcements
**Tags:** release-notes
**Created:** [October 7, 2024, 4:30am UTC](https://meta.discourse.org/t/3-3-2-security-and-maintenance-release/329341 "2024-10-07T04:30:21Z")
**Posts on this page:** 1
**Showing post:** 1

<div class="post-metadata">

### Author: ![mcwumbly](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/mcwumbly/32/103861_2.png) [@mcwumbly](https://meta.discourse.org/u/mcwumbly)
#### Post date: [October 7, 2024, 4:30am UTC](https://meta.discourse.org/t/3-3-2-security-and-maintenance-release/329341/1 "2024-10-07T04:30:21Z")

</div>

## Discourse 3.3.2 Stable Release

Discourse strongly recommends that all sites follow the default tests-passed branch of Discourse. The “stable” branch is more focused on _lack of change_ than _lack of bugs_ - all releases, including those on tests-passed and beta are production ready.

## Security Updates

This release includes fixes for these security issues reported by our community and [HackerOne](https://hackerone.com/discourse).

- DoS by the absence of restrictions on replies to posts ([CVE-2024-43789](https://github.com/discourse/discourse/security/advisories/GHSA-62cq-cpmc-hvqq))
- Bypass of email address validation via encoded email addresses ([CVE-2024-45051](https://github.com/discourse/discourse/security/advisories/GHSA-2vjv-pgh4-6rmq))
- Prevent topic list filtering by hidden tags for unauthorized users ([CVE-2024-45297](https://github.com/discourse/discourse/security/advisories/GHSA-58xw-3qr3-53gp))
- XSS via chat excerpts when CSP disabled ([CVE-2024-47772](https://github.com/discourse/discourse/security/advisories/GHSA-67mh-xhmf-c56h))
- Anonymous cache poisoning via XHR requests ([CVE-2024-47773](https://github.com/discourse/discourse/security/advisories/GHSA-58vv-9j8h-hw2v))

---

_[View the full topic](https://meta.discourse.org/t/3-3-2-security-and-maintenance-release/329341)._
