GHSA-87x6-8m9v-g8c2MediumCVSS 5.3

Portainer CE allows username enumeration through authentication response timing

Published
April 10, 2024
Last Modified
September 30, 2026

🔗 CVE IDs covered (1)

📋 Description

A user enumeration vulnerability was found in Portainer CE 2.19.4. This issue occurs during user authentication process, where a difference in response time could allow a remote unauthenticated user to determine if a username is valid or not.

🎯 Affected products1

  • go/github.com/portainer/portainer:< 0.6.1-0.20240417040827-48bc7d0d92f0

🔗 References (8)