Discourse is an open source platform for community discussion. In affected versions an attacker can learn that a secret subcategory exists under a public category which has no public subcategories. The issue is patched in the latest stable, beta and tests-passed version of Discourse. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Metrics
Affected Vendors & Products
References
History
Wed, 09 Apr 2025 16:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Discourse
Discourse discourse |
|
Weaknesses | NVD-CWE-noinfo | |
CPEs | cpe:2.3:a:discourse:discourse:*:*:*:*:beta:*:*:* cpe:2.3:a:discourse:discourse:*:*:*:*:stable:*:*:* cpe:2.3:a:discourse:discourse:3.2.0:beta1:*:*:beta:*:*:* cpe:2.3:a:discourse:discourse:3.2.0:beta2:*:*:beta:*:*:* cpe:2.3:a:discourse:discourse:3.2.0:beta3:*:*:beta:*:*:* cpe:2.3:a:discourse:discourse:3.2.0:beta4:*:*:beta:*:*:* cpe:2.3:a:discourse:discourse:3.3.0:beta1:*:*:beta:*:*:* |
|
Vendors & Products |
Discourse
Discourse discourse |

Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-27T19:43:50.659Z
Reserved: 2024-01-29T20:51:26.009Z
Link: CVE-2024-24748

Updated: 2024-08-01T23:28:12.640Z

Status : Analyzed
Published: 2024-03-15T20:15:07.677
Modified: 2025-04-09T15:36:23.103
Link: CVE-2024-24748

No data.