Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-54002

Опубликовано: 04 дек. 2024
Источник: nvd
CVSS3: 5.3
EPSS Низкий

Описание

Dependency-Track is a Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain. Performing a login request against the /api/v1/user/login endpoint with a username that exist in the system takes significantly longer than performing the same action with a username that is not known by the system. The observable difference in request duration can be leveraged by actors to enumerate valid names of managed users. LDAP and OpenID Connect users are not affected. The issue has been fixed in Dependency-Track 4.12.2.

EPSS

Процентиль: 30%
0.00114
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-203

EPSS

Процентиль: 30%
0.00114
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-203