CVE-2024-52589

Discourse is an open source platform for community discussion. Moderators can see the Screened emails list in the admin dashboard, and through that can learn the email of a user. This problem is patched in the latest version of Discourse. Users unable to upgrade should remove moderator role from untrusted users.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:discourse:discourse:*:*:*:*:stable:*:*:*
cpe:2.3:a:discourse:discourse:*:*:*:*:beta:*:*:*
cpe:2.3:a:discourse:discourse:3.4.0:beta1:*:*:beta:*:*:*
cpe:2.3:a:discourse:discourse:3.4.0:beta2:*:*:beta:*:*:*

History

26 Aug 2025, 02:16

Type Values Removed Values Added
CWE NVD-CWE-noinfo
First Time Discourse
Discourse discourse
Summary
  • (es) Discourse es una plataforma de código abierto para debates comunitarios. Los moderadores pueden ver la lista de correos electrónicos filtrados en el panel de administración y, a través de ella, pueden conocer el correo electrónico de un usuario. Este problema se solucionó en la última versión de Discourse. Los usuarios que no puedan actualizar deben eliminar el rol de moderador de los usuarios que no sean de confianza.
CPE cpe:2.3:a:discourse:discourse:3.4.0:beta1:*:*:beta:*:*:*
cpe:2.3:a:discourse:discourse:3.4.0:beta2:*:*:beta:*:*:*
cpe:2.3:a:discourse:discourse:*:*:*:*:stable:*:*:*
cpe:2.3:a:discourse:discourse:*:*:*:*:beta:*:*:*
References () https://github.com/discourse/discourse/security/advisories/GHSA-cqw6-rr3v-8fff - () https://github.com/discourse/discourse/security/advisories/GHSA-cqw6-rr3v-8fff - Vendor Advisory

19 Dec 2024, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-12-19 20:15

Updated : 2025-08-26 02:16


NVD link : CVE-2024-52589

Mitre link : CVE-2024-52589

CVE.ORG link : CVE-2024-52589


JSON object : View

Products Affected

discourse

  • discourse
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

NVD-CWE-noinfo