CVE-2024-24748

Discourse is an open source platform for community discussion. In affected versions an attacker can learn that a secret subcategory exists under a public category which has no public subcategories. The issue is patched in the latest stable, beta and tests-passed version of Discourse. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Configurations

No configuration.

History

21 Nov 2024, 08:59

Type Values Removed Values Added
Summary
  • (es) Discourse es una plataforma de código abierto para el debate comunitario. En las versiones afectadas, un atacante puede descubrir que existe una subcategoría secreta en una categoría pública que no tiene subcategorías públicas. El problema está solucionado en la última versión estable, beta y probada de Discourse. Se recomienda a los usuarios que actualicen. No se conocen workarounds para esta vulnerabilidad.
References () https://github.com/discourse/discourse/commit/819361ba28f86a1347059af300bb5cca690f9193 - () https://github.com/discourse/discourse/commit/819361ba28f86a1347059af300bb5cca690f9193 -
References () https://github.com/discourse/discourse/security/advisories/GHSA-3qh8-xw23-cq4x - () https://github.com/discourse/discourse/security/advisories/GHSA-3qh8-xw23-cq4x -

15 Mar 2024, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-03-15 20:15

Updated : 2024-11-21 08:59


NVD link : CVE-2024-24748

Mitre link : CVE-2024-24748

CVE.ORG link : CVE-2024-24748


JSON object : View

Products Affected

No product.

CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor