# 3.3.4: Security and maintenance release

**URL:** https://meta.discourse.org/t/3-3-4-security-and-maintenance-release/349301
**Category:** Announcements
**Tags:** release-notes
**Created:** [February 5, 2025, 2:26pm UTC](https://meta.discourse.org/t/3-3-4-security-and-maintenance-release/349301 "2025-02-05T14:26:22Z")
**Posts on this page:** 1
**Page:** 1

<div class="post-metadata">

### Author: ![Saif](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/saif/32/318253_2.png) [@Saif](https://meta.discourse.org/u/Saif)
#### Post date: [February 5, 2025, 2:26pm UTC](https://meta.discourse.org/t/3-3-4-security-and-maintenance-release/349301/1 "2025-02-05T14:26:22Z")

</div>

## Discourse 3.3.4 Stable Release

Discourse strongly recommends that all sites follow the default tests-passed branch of Discourse. The “stable” branch is more focused on _lack of change_ than _lack of bugs_ - all releases, including those on tests-passed and beta are production ready.

## Security Updates

This release includes fixes for these security issues reported by our community and [HackerOne](https://hackerone.com/discourse).

- XSS via topic titles when CSP disabled ([CVE-2024-53266](https://github.com/discourse/discourse/security/advisories/GHSA-hw4j-4hg7-22h2))
- Partial DoS via inline oneboxes ([CVE-2024-53851](https://github.com/discourse/discourse/security/advisories/GHSA-49rv-574x-wgpc))
- Potential bypass of chat permissions ([CVE-2024-53994](https://github.com/discourse/discourse/security/advisories/GHSA-mrpw-gwj7-98r6))
- Users can see other user’s tagged PMs ([CVE-2024-56197](https://github.com/discourse/discourse/security/advisories/GHSA-xmgr-g9cp-v239))
- HTMLi(XSS without CSP) via Onebox URLs ([CVE-2024-56328](https://github.com/discourse/discourse/security/advisories/GHSA-j855-mhxj-x6vg))
- Stored DOM-based XSS (without CSP) via video placeholders ([CVE-2025-22602](https://github.com/discourse/discourse/security/advisories/GHSA-jcjx-694p-c5m3))
- Anonymous cache poisoning via XHR requests ([CVE-2024-55948](https://github.com/discourse/discourse/security/advisories/GHSA-2352-252q-qc82))
- Anonymous cache poisoning via request headers ([CVE-2025-23023](https://github.com/discourse/discourse/security/advisories/GHSA-5h4h-2f46-r3c7))
