CVE-2024-28232

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-28232
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-28232.json
Aliases
Published
2024-04-01T17:15:45Z
Modified
2024-04-02T19:56:33.105529Z
Details

Go package IceWhaleTech/CasaOS-UserService provides user management functionalities to CasaOS. The Casa OS Login page has disclosed the username enumeration vulnerability in the login page which was patched in version 0.4.7. This issue in CVE-2024-28232 has been patched in version 0.4.8 but that version has not yet been uploaded to Go's package manager.

References

Affected packages

Git / github.com/IceWhaleTech/CasaOS-UserService

Affected ranges

Type
GIT
Repo
https://github.com/IceWhaleTech/CasaOS-UserService
Events
Introduced
0The exact introduced commit is unknown
Fixed

Affected versions

v0.*

v0.3.5-alpha1
v0.3.5-alpha2
v0.3.5-alpha3
v0.3.6
v0.3.6-alpha1
v0.3.6-alpha2
v0.3.6-alpha3
v0.3.6-alpha4
v0.3.6-alpha5
v0.3.6-alpha6
v0.3.6-alpha7
v0.3.7
v0.3.7-alpha1
v0.3.7-alpha2
v0.4.0
v0.4.0-alpha1
v0.4.0-alpha2
v0.4.0-alpha3
v0.4.0-alpha4
v0.4.0-alpha5
v0.4.0-alpha6
v0.4.1
v0.4.1-alpha1
v0.4.1-alpha2
v0.4.2
v0.4.2-alpha1
v0.4.4
v0.4.4-2-alpha1
v0.4.4-3-alpha1
v0.4.4-3-alpha2
v0.4.4-3-alpha3
v0.4.4-alpha1
v0.4.4-alpha2
v0.4.4-alpha3
v0.4.4-alpha5
v0.4.4-alpha6
v0.4.4-alpha7
v0.4.4-alpha8
v0.4.5
v0.4.6-alpha1
v0.4.6-alpha2
v0.4.6-alpha3
v0.4.7
v0.4.7-alpha1