← Back

CVE-2024-24748

nvd nist
Published: Mar 15, 2024Modified: Apr 9, 2025

JSON object

Loading...
5.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Exploitability: 3.9 / Impact: 1.4
Source: NVD

Description

Discourse is an open source platform for community discussion. In affected versions an attacker can learn that a secret subcategory exists under a public category which has no public subcategories. The issue is patched in the latest stable, beta and tests-passed version of Discourse. Users are advised to upgrade. There are no known workarounds for this vulnerability.

Affected (7)

Products: Discourse: Discourse
1 product
Discourse
Configuration A
7 vulnerable
Vulnerable SoftwareAffected Versions
Discourse
Up to 3.2.0
Up to 3.2.0
Version 3.2.0 beta1
Version 3.2.0 beta2
Version 3.2.0 beta3
Version 3.2.0 beta4
Version 3.3.0 beta1

References (4)

Timeline

No history available yet.