Description
Discourse is an open source platform for community discussion. In affected versions an attacker can learn that a secret subcategory exists under a public category which has no public subcategories. The issue is patched in the latest stable, beta and tests-passed version of Discourse. Users are advised to upgrade. There are no known workarounds for this vulnerability.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-22146 | Discourse is an open source platform for community discussion. In affected versions an attacker can learn that a secret subcategory exists under a public category which has no public subcategories. The issue is patched in the latest stable, beta and tests-passed version of Discourse. Users are advised to upgrade. There are no known workarounds for this vulnerability. |
References
History
Wed, 09 Apr 2025 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Discourse
Discourse discourse |
|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:discourse:discourse:*:*:*:*:beta:*:*:* cpe:2.3:a:discourse:discourse:*:*:*:*:stable:*:*:* cpe:2.3:a:discourse:discourse:3.2.0:beta1:*:*:beta:*:*:* cpe:2.3:a:discourse:discourse:3.2.0:beta2:*:*:beta:*:*:* cpe:2.3:a:discourse:discourse:3.2.0:beta3:*:*:beta:*:*:* cpe:2.3:a:discourse:discourse:3.2.0:beta4:*:*:beta:*:*:* cpe:2.3:a:discourse:discourse:3.3.0:beta1:*:*:beta:*:*:* |
|
| Vendors & Products |
Discourse
Discourse discourse |
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-27T19:43:50.659Z
Reserved: 2024-01-29T20:51:26.009Z
Link: CVE-2024-24748
Updated: 2024-08-01T23:28:12.640Z
Status : Analyzed
Published: 2024-03-15T20:15:07.677
Modified: 2025-04-09T15:36:23.103
Link: CVE-2024-24748
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD