CVE-2024-52297

Tolgee is an open-source localization platform. Tolgee 3.81.1 included the all configuration properties in the PublicConfiguratioDTO publicly exposed to users. This vulnerability is fixed in v3.81.2.
Configurations

Configuration 1 (hide)

cpe:2.3:a:tolgee:tolgee:3.81.1:*:*:*:*:*:*:*

History

11 Sep 2025, 21:27

Type Values Removed Values Added
First Time Tolgee
Tolgee tolgee
CPE cpe:2.3:a:tolgee:tolgee:3.81.1:*:*:*:*:*:*:*
References () https://github.com/tolgee/tolgee-platform/pull/2481/files#diff-d16735590f0f2db7cd782e2966fa18426b94b5e4030fa8b1f5e00cd55686fe7f - () https://github.com/tolgee/tolgee-platform/pull/2481/files#diff-d16735590f0f2db7cd782e2966fa18426b94b5e4030fa8b1f5e00cd55686fe7f - Patch
References () https://github.com/tolgee/tolgee-platform/pull/2689/files - () https://github.com/tolgee/tolgee-platform/pull/2689/files - Patch
References () https://github.com/tolgee/tolgee-platform/security/advisories/GHSA-3wr3-889v-pgcj - () https://github.com/tolgee/tolgee-platform/security/advisories/GHSA-3wr3-889v-pgcj - Vendor Advisory

13 Nov 2024, 17:01

Type Values Removed Values Added
Summary
  • (es) Tolgee es una plataforma de localización de código abierto. Tolgee 3.81.1 incluía todas las propiedades de configuración en PublicConfiguratioDTO, expuestas públicamente a los usuarios. Esta vulnerabilidad se solucionó en la versión 3.81.2.

12 Nov 2024, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-11-12 16:15

Updated : 2025-09-11 21:27


NVD link : CVE-2024-52297

Mitre link : CVE-2024-52297

CVE.ORG link : CVE-2024-52297


JSON object : View

Products Affected

tolgee

  • tolgee
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor