Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-28242


Discourse is an open source platform for community discussion. In affected versions an attacker can learn that secret categories exist when they have backgrounds set. The issue is patched in the latest stable, beta and tests-passed version of Discourse. Users are advised to upgrade. Users unable to upgrade should temporarily remove category backgrounds.


Published

2024-03-15T20:15:09.587

Last Modified

2025-09-26T12:50:32.323

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 5.3 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-200

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application discourse discourse < 3.2.0 Yes
Application discourse discourse < 3.3.0 Yes
Application discourse discourse 3.3.0 Yes
Application discourse discourse 3.3.0 Yes

References