Galette Fixes Security Issue in Public Pages
CVE-2024-24761
7.5HIGH
What is CVE-2024-24761?
The vulnerability in Galette, a web application designed for managing memberships in non-profit organizations, presents a security risk where public pages are, by default, accessible only to administrators and staff members. This configuration issue permits unauthorized access if the software is operated on outdated versions prior to 1.0.2, where improper configuration may allow non-privileged users to view public content. Version 1.0.2 addresses this concern by correcting the default access settings, thus enhancing the security posture for organizations utilizing this application.
Affected Version(s)
galette >= 1.0.0, < 1.0.2
