Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-28232

Опубликовано: 01 апр. 2024
Источник: nvd
CVSS3: 6.2
CVSS3: 7.5
EPSS Низкий

Описание

Go package IceWhaleTech/CasaOS-UserService provides user management functionalities to CasaOS. The Casa OS Login page has disclosed the username enumeration vulnerability in the login page which was patched in version 0.4.7. This issue in CVE-2024-28232 has been patched in version 0.4.8 but that version has not yet been uploaded to Go's package manager.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:icewhale:casaos-userservice:0.4.7:-:*:*:*:*:*:*

EPSS

Процентиль: 49%
0.00262
Низкий

6.2 Medium

CVSS3

7.5 High

CVSS3

Дефекты

CWE-204

Связанные уязвимости

CVSS3: 6.2
github
почти 2 года назад

CasaOS Username Enumeration - Bypass of CVE-2024-24766

EPSS

Процентиль: 49%
0.00262
Низкий

6.2 Medium

CVSS3

7.5 High

CVSS3

Дефекты

CWE-204