CRITICAL
Tolgee's configuration all configuration properties leaked in public configuration DTO
Published Nov 12, 2024
9.8
CRITICALCVSS 3.1
EPSS 0.60%
Description
Tolgee is an open-source localization platform. Tolgee 3.81.1 included the all configuration properties in the PublicConfiguratioDTO publicly exposed to users. This vulnerability is fixed in v3.81.2.
Affected products
-
- Version >= 3.81.1, < 3.81.2StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Tolgee | Tolgee-Platform | n/a |
|
-
- Version 0StatusaffectedConstraints<=3.81.1
- Version 0StatusaffectedConstraints<3.81.2
- Version
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (3)
- https://github.com/tolgee/tolgee-platform/pull/2481/files#diff-d16735590f0f2db7cd782e2966fa18426b94b5e4030fa8b1f5e00cd55686fe7f x_refsource_MISCPatch
- https://github.com/tolgee/tolgee-platform/pull/2689/files x_refsource_MISCPatch
- https://github.com/tolgee/tolgee-platform/security/advisories/GHSA-3wr3-889v-pgcj x_refsource_CONFIRMVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://github.com/tolgee/tolgee-platform/pull/2481/files#diff-d16735590f0f2db7cd782e2966fa18426b94b5e4030fa8b1f5e00cd55686fe7f | x_refsource_MISCPatch | |
| https://github.com/tolgee/tolgee-platform/pull/2689/files | x_refsource_MISCPatch | |
| https://github.com/tolgee/tolgee-platform/security/advisories/GHSA-3wr3-889v-pgcj | x_refsource_CONFIRMVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Nov 12, 2024
Updated Nov 12, 2024
Reserved Nov 6, 2024
Link CVE-2024-52297
CISA Vulnrichment
Updated Nov 12, 2024