First published: Thu Feb 01 2024(Updated: )
discourse-group-membership-ip-block is a discourse plugin that adds support for adding users to groups based on their IP address. discourse-group-membership-ip-block was sending all group custom fields to the client, including group custom fields from other plugins which may expect their custom fields to remain secret.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
Discourse Group Membership Ip Blocks |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-24755 has a moderate severity rating due to the potential exposure of sensitive group custom fields.
To fix CVE-2024-24755, update the Discourse Group Membership IP Block plugin to the latest version where the issue has been patched.
CVE-2024-24755 can lead to unintended information disclosure as it exposes group custom fields to clients.
CVE-2024-24755 affects the Discourse Group Membership IP Blocks plugin.
The impact of CVE-2024-24755 on user data is that it may lead to unauthorized users gaining access to sensitive group information.