Improper Authorization in Discourse - CVE-2024-24748
Published: March 15, 2024 / Updated: July 1, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper authorization in secret subcategory handling when accessing a public category with no public subcategories. A remote attacker can determine that a secret subcategory exists to disclose sensitive information.