CVE-2024-24755 - CVE House
Back to Database
Status published Medium CVE-2024-24755

discourse-group-membership-ip-block is exposing potentially sensitive custom fields

Vulnerability Description

discourse-group-membership-ip-block is a discourse plugin that adds support for adding users to groups based on their IP address. discourse-group-membership-ip-block was sending all group custom fields to the client, including group custom fields from other plugins which may expect their custom fields to remain secret.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-24755

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

discourse-group-membership-ip-block
Vulnerable Versions:
< b394d61b0bdfd18a2d8310aa5cf26cccf8bd31c1

Timeline

Official Publish: February 1st, 2024
Last Modified: August 1st, 2024
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Weaknesses (CWE)