CVE-2024-24748
Discourse is an open source platform for community discussion. In affected versions an attacker can learn that a secret
Discourse is an open source platform for community discussion. In affected versions an attacker can learn that a secret subcategory exists under a public category which has no public subcategories. The issue is patched in the latest stable, beta and tests-passed version of Discourse.
Users are advised to upgrade. There are no known workarounds for this vulnerability.
MEDIUM · CVSS 5.3
EPSS 0.00109
Schedule remediation
- SSVC automatable: yes - attacks can be scripted at scale
Sigma rules0
YARA rules0