7.5
CVE-2024-28242
- EPSS 0.49%
- Veröffentlicht 15.03.2024 20:15:09
- Zuletzt bearbeitet 26.09.2025 12:50:32
- Quelle security-advisories@github.com
- CVE-Watchlists
- Unerledigt
Disclosure of the existence of secret categories with custom backgrounds in Discourse
Discourse is an open source platform for community discussion. In affected versions an attacker can learn that secret categories exist when they have backgrounds set. The issue is patched in the latest stable, beta and tests-passed version of Discourse. Users are advised to upgrade. Users unable to upgrade should temporarily remove category backgrounds.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.49% | 0.384 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
| security-advisories@github.com | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
https://github.com/discourse/discourse/commit/b425fbc2a28341a5627928f963519006712c3d39
https://github.com/discourse/discourse/security/advisories/GHSA-c7q7-7f6q-2c23