Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-24755


discourse-group-membership-ip-block is a discourse plugin that adds support for adding users to groups based on their IP address. discourse-group-membership-ip-block was sending all group custom fields to the client, including group custom fields from other plugins which may expect their custom fields to remain secret.


Published

2024-02-01T22:15:55.900

Last Modified

2024-11-21T08:59:37.990

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 4.3 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-200
  • Type: Primary
    NVD-CWE-noinfo

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application discourse group_membership_ip_blocks - Yes

References