CVE-2024-24755: discourse-group-membership-ip-block is exposing potentially sensitive custom fields
discourse-group-membership-ip-block is a discourse plugin that adds support for adding users to groups based on their IP address. discourse-group-membership-ip-block was sending all group custom fields to the client, including group custom fields from other plugins which may expect their custom fields to remain secret.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-24755?
CVE-2024-24755 has a moderate severity rating due to the potential exposure of sensitive group custom fields.
How do I fix CVE-2024-24755?
To fix CVE-2024-24755, update the Discourse Group Membership IP Block plugin to the latest version where the issue has been patched.
What vulnerabilities are associated with CVE-2024-24755?
CVE-2024-24755 can lead to unintended information disclosure as it exposes group custom fields to clients.
Which software is affected by CVE-2024-24755?
CVE-2024-24755 affects the Discourse Group Membership IP Blocks plugin.
What is the impact of CVE-2024-24755 on user data?
The impact of CVE-2024-24755 on user data is that it may lead to unauthorized users gaining access to sensitive group information.