CVE-2024-24766
Username enumeration in github.com/IceWhaleTech/CasaOS-UserService
6.2
MEDIUM
CVSS 3.1
EPSS 0.76%
Description
CasaOS-UserService is vulnerable to a username enumeration issue, when an attacker can enumerate the CasaOS username using the application response. If the username is incorrect, the application gives the error 'User does not exist'. If the password is incorrect, the application gives the error 'Invalid password'.
How to fix CVE-2024-24766
To remediate CVE-2024-24766, upgrade the affected package to a fixed version below.
- —upgrade to 0.4.7 or later
- —upgrade to 0.4.7 or later
Is CVE-2024-24766 being exploited?
Low — EPSS is 0.8%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- >= 0.4.4.3, < 0.4.7
- >= 0.4.4-3-alpha1, < 0.4.7
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM6.2 | CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |