Vulnerability Description
discourse-group-membership-ip-block is a discourse plugin that adds support for adding users to groups based on their IP address. discourse-group-membership-ip-block was sending all group custom fields to the client, including group custom fields from other plugins which may expect their custom fields to remain secret.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Discourse | Group Membership Ip Blocks | - |
Related Weaknesses (CWE)
References
- https://github.com/discourse/discourse-group-membership-ip-block/commit/b394d61bPatch
- https://github.com/discourse/discourse-group-membership-ip-block/security/advisoVendor Advisory
- https://github.com/discourse/discourse-group-membership-ip-block/commit/b394d61bPatch
- https://github.com/discourse/discourse-group-membership-ip-block/security/advisoVendor Advisory
FAQ
What is CVE-2024-24755?
CVE-2024-24755 is a vulnerability with a CVSS score of 4.3 (MEDIUM). discourse-group-membership-ip-block is a discourse plugin that adds support for adding users to groups based on their IP address. discourse-group-membership-ip-block was sending all group custom field...
How severe is CVE-2024-24755?
CVE-2024-24755 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-24755?
Check the references section above for vendor advisories and patch information. Affected products include: Discourse Group Membership Ip Blocks.