CVE Feed

    Dashboard / CVE / CVE-2024-24766

    CVE-2024-24766

    CasaOS-UserService provides user management functionalities to CasaOS. Starting in version 0.4.4.3 and prior to version 0.4.7, the Casa OS Login page disclosed the username enumeration vulnerability in the login page. An attacker can enumerate the CasaOS username using the application response. If the username is incorrect application gives the error `**User does not exist**`. If the password is incorrect application gives the error `**Invalid password**`. Version 0.4.7 fixes this issue.

    Published:Mar 6, 2024
    Last Modified:May 28, 2025
    EPS:Mar 6, 2024
    EPSS Score:0.00357
    CVSS Score:6.2

    Affected Products

    Vendor
    Icewhale
    Product
    Casaos-userservice

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High