CVE-2024-28232

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-28232
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-28232.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-28232
Aliases
Published
2024-04-01T16:42:05Z
Modified
2025-10-15T09:09:33.360358Z
Severity
  • 6.2 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
Username Enumeration in CasaOS via bypass of CVE-2024-24766
Details

Go package IceWhaleTech/CasaOS-UserService provides user management functionalities to CasaOS. The Casa OS Login page has disclosed the username enumeration vulnerability in the login page which was patched in version 0.4.7. This issue in CVE-2024-28232 has been patched in version 0.4.8 but that version has not yet been uploaded to Go's package manager.

References

Affected packages

Git / github.com/IceWhaleTech/CasaOS-UserService

Affected ranges

Type
GIT
Repo
https://github.com/IceWhaleTech/CasaOS-UserService
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected

Affected versions

v0.*

v0.3.5-alpha1
v0.3.5-alpha2
v0.3.5-alpha3
v0.3.6
v0.3.6-alpha1
v0.3.6-alpha2
v0.3.6-alpha3
v0.3.6-alpha4
v0.3.6-alpha5
v0.3.6-alpha6
v0.3.6-alpha7
v0.3.7
v0.3.7-alpha1
v0.3.7-alpha2
v0.4.0
v0.4.0-alpha1
v0.4.0-alpha2
v0.4.0-alpha3
v0.4.0-alpha4
v0.4.0-alpha5
v0.4.0-alpha6
v0.4.1
v0.4.1-alpha1
v0.4.1-alpha2
v0.4.2
v0.4.2-alpha1
v0.4.4
v0.4.4-2-alpha1
v0.4.4-3-alpha1
v0.4.4-3-alpha2
v0.4.4-3-alpha3
v0.4.4-alpha1
v0.4.4-alpha2
v0.4.4-alpha3
v0.4.4-alpha5
v0.4.4-alpha6
v0.4.4-alpha7
v0.4.4-alpha8
v0.4.5
v0.4.6-alpha1
v0.4.6-alpha2
v0.4.6-alpha3
v0.4.7

Git / github.com/IceWhaleTech/CasaOS-UserService

Affected ranges

Type
GIT
Repo
https://github.com/IceWhaleTech/CasaOS-UserService
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected

Affected versions

v0.*

v0.3.5-alpha1
v0.3.5-alpha2
v0.3.5-alpha3
v0.3.6
v0.3.6-alpha1
v0.3.6-alpha2
v0.3.6-alpha3
v0.3.6-alpha4
v0.3.6-alpha5
v0.3.6-alpha6
v0.3.6-alpha7
v0.3.7
v0.3.7-alpha1
v0.3.7-alpha2
v0.4.0
v0.4.0-alpha1
v0.4.0-alpha2
v0.4.0-alpha3
v0.4.0-alpha4
v0.4.0-alpha5
v0.4.0-alpha6
v0.4.1
v0.4.1-alpha1
v0.4.1-alpha2
v0.4.2
v0.4.2-alpha1
v0.4.4
v0.4.4-2-alpha1
v0.4.4-3-alpha1
v0.4.4-3-alpha2
v0.4.4-3-alpha3
v0.4.4-alpha1
v0.4.4-alpha2
v0.4.4-alpha3
v0.4.4-alpha5
v0.4.4-alpha6
v0.4.4-alpha7
v0.4.4-alpha8
v0.4.5
v0.4.6-alpha1
v0.4.6-alpha2
v0.4.6-alpha3
v0.4.7