GHSA-87x6-8m9v-g8c2MediumCVSS 5.3
Portainer CE allows username enumeration through authentication response timing
🔗 CVE IDs covered (1)
📋 Description
A user enumeration vulnerability was found in Portainer CE 2.19.4. This issue occurs during user authentication process, where a difference in response time could allow a remote unauthenticated user to determine if a username is valid or not.
🎯 Affected products1
- go/github.com/portainer/portainer:< 0.6.1-0.20240417040827-48bc7d0d92f0
🔗 References (8)
- https://nvd.nist.gov/vuln/detail/CVE-2024-29296
- https://github.com/ThaySolis/CVE-2024-29296
- https://github.com/portainer/portainer/issues/11736
- https://github.com/portainer/portainer/pull/11589
- https://github.com/portainer/portainer/commit/48bc7d0d92f038e04a72c1e0585bc325eb63a9e6
- https://github.com/portainer/portainer/releases/tag/2.19.5
- https://github.com/portainer/portainer/releases/tag/2.20.2
- https://github.com/advisories/GHSA-87x6-8m9v-g8c2