CVE-2024-24761

Galette is a membership management web application for non profit organizations. Starting in version 1.0.0 and prior to version 1.0.2, public pages are per default restricted to only administrators and staff members. From configuration, it is possible to restrict to up-to-date members or to everyone. Version 1.0.2 fixes this issue.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:galette:galette:1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:galette:galette:1.0.1:*:*:*:*:*:*:*

History

17 Dec 2024, 20:06

Type Values Removed Values Added
First Time Galette galette
Galette
CPE cpe:2.3:a:galette:galette:1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:galette:galette:1.0.1:*:*:*:*:*:*:*
References () https://github.com/galette/galette/commit/a5c18bb9819b8da1b3ef58f3e79577083c657fbb - () https://github.com/galette/galette/commit/a5c18bb9819b8da1b3ef58f3e79577083c657fbb - Patch
References () https://github.com/galette/galette/security/advisories/GHSA-jrqg-mpwv-pxpv - () https://github.com/galette/galette/security/advisories/GHSA-jrqg-mpwv-pxpv - Vendor Advisory

21 Nov 2024, 08:59

Type Values Removed Values Added
References () https://github.com/galette/galette/commit/a5c18bb9819b8da1b3ef58f3e79577083c657fbb - () https://github.com/galette/galette/commit/a5c18bb9819b8da1b3ef58f3e79577083c657fbb -
References () https://github.com/galette/galette/security/advisories/GHSA-jrqg-mpwv-pxpv - () https://github.com/galette/galette/security/advisories/GHSA-jrqg-mpwv-pxpv -
Summary
  • (es) Galette es una aplicación web de gestión de membresías para organizaciones sin fines de lucro. A partir de la versión 1.0.0 y antes de la versión 1.0.2, las páginas públicas están restringidas de forma predeterminada solo a administradores y miembros del personal. Desde la configuración es posible restringir a miembros actualizados o a todos. La versión 1.0.2 soluciona este problema.

06 Mar 2024, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-03-06 18:15

Updated : 2024-12-17 20:06


NVD link : CVE-2024-24761

Mitre link : CVE-2024-24761

CVE.ORG link : CVE-2024-24761


JSON object : View

Products Affected

galette

  • galette
CWE
CWE-863

Incorrect Authorization