CVE-2024-52589

LOW

Discourse - Unauthorized Exposure of User Email via Moderator Dashboard

Title source: llm
STIX 2.1

Description

Discourse is an open source platform for community discussion. Moderators can see the Screened emails list in the admin dashboard, and through that can learn the email of a user. This problem is patched in the latest version of Discourse. Users unable to upgrade should remove moderator role from untrusted users.

References (1)

Core 1
Core References

Scores

CVSS v3 2.2
EPSS 0.0041
EPSS Percentile 61.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-200
Status published
Products (3)
discourse/discourse 3.4.0 beta1 (2 CPE variants)
discourse/discourse < 3.3.3
discourse/discourse < 3.4.0
Published Dec 19, 2024
Tracked Since Feb 18, 2026