PT-2024-20583 · Discourse · Discourse Calendar
0-0Eth0
+1
·
Published
2024-02-22
·
Updated
2025-02-05
·
CVE-2024-24817
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Discourse Calendar versions prior to 0.4
Description
The issue allows event invitees created in private categories or private messages to be retrieved by anyone, even if they are not logged in. This is a problem with the Discourse Calendar plugin for the open-source discussion platform Discourse. There is no known workaround, but putting the site behind
login required can disallow the use of this endpoint by anonymous users. However, logged-in users can still get the list of invitees in private topics.Recommendations
For versions prior to 0.4, update to version 0.4 of the discourse-calendar plugin to resolve the issue.
As a temporary workaround, consider putting the site behind
login required to disallow the use of the vulnerable endpoint by anonymous users.Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Discourse Calendar