CVE-2024-24755

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
01/02/2024
Last modified:
09/02/2024

Description

discourse-group-membership-ip-block is a discourse plugin that adds support for adding users to groups based on their IP address. discourse-group-membership-ip-block was sending all group custom fields to the client, including group custom fields from other plugins which may expect their custom fields to remain secret.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:discourse:group_membership_ip_blocks:-:*:*:*:*:*:*:*