Tolgee is an open-source localization platform. Tolgee 3.81.1 included the all configuration properties in the PublicConfiguratioDTO publicly exposed to users. This vulnerability is fixed in v3.81.2.
History

Tue, 12 Nov 2024 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Tolgee
Tolgee tolgee
CPEs cpe:2.3:a:tolgee:tolgee:*:*:*:*:*:*:*:*
Vendors & Products Tolgee
Tolgee tolgee
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 12 Nov 2024 16:00:00 +0000

Type Values Removed Values Added
Description Tolgee is an open-source localization platform. Tolgee 3.81.1 included the all configuration properties in the PublicConfiguratioDTO publicly exposed to users. This vulnerability is fixed in v3.81.2.
Title Tolgee's configuration all configuration properties leaked in public configuration DTO
Weaknesses CWE-200
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2024-11-12T15:54:29.775Z

Updated: 2024-11-12T18:37:23.313Z

Reserved: 2024-11-06T19:00:26.395Z

Link: CVE-2024-52297

cve-icon Vulnrichment

Updated: 2024-11-12T18:37:12.817Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-11-12T16:15:26.230

Modified: 2024-11-13T17:01:58.603

Link: CVE-2024-52297

cve-icon Redhat

No data.