# 3.3.4：安全和维护版本

**URL:** <https://meta.discourse.org/t/3-3-4-security-and-maintenance-release/349301>\
**Category:** Announcements\
**Tags:** release-notes\
**Created:** [2025年二月5日 14:26 UTC](https://meta.discourse.org/t/3-3-4-security-and-maintenance-release/349301 "2025-02-05T14:26:22Z")\
**Posts on this page:** 1\
**Showing post:** 1

<div class="post-metadata">

**Author:** ![Saif](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/saif/32/318253_2.png) [@Saif](https://meta.discourse.org/u/Saif)\
**Post date:** [2025年二月5日 14:26 UTC](https://meta.discourse.org/t/3-3-4-security-and-maintenance-release/349301/1 "2025-02-05T14:26:22Z")

</div>

## Discourse 3.3.4 稳定版发布

Discourse 强烈建议所有站点遵循 Discourse 的默认 tests-passed 分支。 “stable” 分支更侧重于_不变性_而非_无 bug_——所有版本，包括 tests-passed 和 beta 版本，都已准备好投入生产。

## 安全更新

此版本包含对我们社区和 [HackerOne](https://hackerone.com/discourse) 报告的以下安全问题的修复。

- 在 CSP 禁用时通过主题标题进行 XSS（[CVE-2024-53266](https://github.com/discourse/discourse/security/advisories/GHSA-hw4j-4hg7-22h2)）
- 通过内联 onebox 进行部分 DoS（[CVE-2024-53851](https://github.com/discourse/discourse/security/advisories/GHSA-49rv-574x-wgpc)）
- 可能绕过聊天权限（[CVE-2024-53994](https://github.com/discourse/discourse/security/advisories/GHSA-mrpw-gwj7-98r6)）
- 用户可以看到其他用户的标记私信（[CVE-2024-56197](https://github.com/discourse/discourse/security/advisories/GHSA-xmgr-g9cp-v239)）
- 通过 Onebox URL 进行 HTML 注入（无 CSP 的 XSS）（[CVE-2024-56328](https://github.com/discourse/discourse/security/advisories/GHSA-j855-mhxj-x6vg)）
- 通过视频占位符进行存储型 DOM 型 XSS（无 CSP）（[CVE-2025-22602](https://github.com/discourse/discourse/security/advisories/GHSA-jcjx-694p-c5m3)）
- 通过 XHR 请求进行匿名缓存投毒（[CVE-2024-55948](https://github.com/discourse/discourse/security/advisories/GHSA-2352-252q-qc82)）
- 通过请求头进行匿名缓存投毒（[CVE-2025-23023](https://github.com/discourse/discourse/security/advisories/GHSA-5h4h-2f46-r3c7)）

---

_[View the full topic](https://meta.discourse.org/t/3-3-4-security-and-maintenance-release/349301)._
