CVE-2024-24766

Source
https://cve.org/CVERecord?id=CVE-2024-24766
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-24766.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-24766
Aliases
Related
Published
2024-03-06T18:10:25.869Z
Modified
2026-03-12T00:40:04.233566Z
Severity
  • 6.2 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
CasaOS Username Enumeration
Details

CasaOS-UserService provides user management functionalities to CasaOS. Starting in version 0.4.4.3 and prior to version 0.4.7, the Casa OS Login page disclosed the username enumeration vulnerability in the login page. An attacker can enumerate the CasaOS username using the application response. If the username is incorrect application gives the error **User does not exist**. If the password is incorrect application gives the error **Invalid password**. Version 0.4.7 fixes this issue.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-204"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/24xxx/CVE-2024-24766.json"
}
References

Affected packages

Git /

Affected ranges

Type
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
c75063d7ca5800948e9c09c0a6efe9809b5d39f7
Type
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
7bd0df6441c25c322460f75c55bf18fe908441f9

Database specific

unresolved_ranges
[
    {
        "events": [
            {
                "introduced": "0.4.4-3"
            },
            {
                "last_affected": "0.4.7"
            }
        ]
    }
]
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-24766.json"