In Discourse 2.7.0 through beta1, a rate-limit bypass leads to a bypass of the 2FA requirement for certain forms.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2021-3138.json"