First published: Fri Mar 15 2024(Updated: )
Discourse is an open source platform for community discussion. In affected versions an attacker can learn that a secret subcategory exists under a public category which has no public subcategories. The issue is patched in the latest stable, beta and tests-passed version of Discourse. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
Discourse | <latest stable<beta<tests-passed |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-24748 has been classified as a medium severity vulnerability affecting the Discourse platform.
To fix CVE-2024-24748, upgrade Discourse to the latest stable, beta, or tests-passed version.
An attacker can uncover the existence of a secret subcategory within a public category that has no visible subcategories due to this vulnerability.
CVE-2024-24748 affects prior versions of Discourse before the fixes were applied in the latest stable, beta, and tests-passed versions.
Yes, a patch for CVE-2024-24748 is available in the latest stable, beta, and tests-passed versions of Discourse.