CVE-2024-24755

discourse-group-membership-ip-block is a discourse plugin that adds support for adding users to groups based on their IP address. discourse-group-membership-ip-block was sending all group custom fields to the client, including group custom fields from other plugins which may expect their custom fields to remain secret.
Configurations

Configuration 1 (hide)

cpe:2.3:a:discourse:group_membership_ip_blocks:-:*:*:*:*:*:*:*

History

09 Feb 2024, 19:47

Type Values Removed Values Added
CPE cpe:2.3:a:discourse:group_membership_ip_blocks:-:*:*:*:*:*:*:*
References () https://github.com/discourse/discourse-group-membership-ip-block/commit/b394d61b0bdfd18a2d8310aa5cf26cccf8bd31c1 - () https://github.com/discourse/discourse-group-membership-ip-block/commit/b394d61b0bdfd18a2d8310aa5cf26cccf8bd31c1 - Patch
References () https://github.com/discourse/discourse-group-membership-ip-block/security/advisories/GHSA-r38c-cp8w-664m - () https://github.com/discourse/discourse-group-membership-ip-block/security/advisories/GHSA-r38c-cp8w-664m - Vendor Advisory
CWE NVD-CWE-noinfo
First Time Discourse group Membership Ip Blocks
Discourse
CVSS v2 : unknown
v3 : 4.3
v2 : unknown
v3 : 5.3
Summary
  • (es) discourse-group-membership-ip-block es un complemento de discourse que agrega soporte para agregar usuarios a grupos según su dirección IP. discourse-group-membership-ip-block estaba enviando todos los campos personalizados del grupo al cliente, incluidos los campos personalizados del grupo de otros complementos que pueden esperar que sus campos personalizados permanezcan en secreto.

01 Feb 2024, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-01 22:15

Updated : 2024-02-09 19:47


NVD link : CVE-2024-24755

Mitre link : CVE-2024-24755

CVE.ORG link : CVE-2024-24755


JSON object : View

Products Affected

discourse

  • group_membership_ip_blocks
CWE
NVD-CWE-noinfo CWE-200

Exposure of Sensitive Information to an Unauthorized Actor