Improper Authorization in Discourse - CVE-2024-28242

 

Improper Authorization in Discourse - CVE-2024-28242

Published: March 15, 2024 / Updated: July 1, 2026


Vulnerability identifier: #VU136098
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-28242
CWE-ID: CWE-285
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to improper authorization in secret categories with custom backgrounds when rendering category backgrounds. A remote attacker can access affected content handling to disclose sensitive information.

The issue can reveal the existence of secret categories when category backgrounds are set.


Affected software

Discourse

How to mitigate CVE-2024-28242

Install security update from vendor's website.

Discourse - addressed in versions 3.2.1, 3.3.0 beta2

External References

Related Security Bulletins