GO-2024-2668

    Dashboard / Vulnerabilities / GO-2024-2668

    GO-2024-2668

    Published: 2 Apr 2024Last Modified: 20 May 2024

    Summary: Login username enumeration in github.com/IceWhaleTech/CasaOS-UserService

    Details: The Casa OS Login page has a username enumeration vulnerability in the login page that was patched in Casa OS v0.4.7. The issue exists because the application response differs depending on whether the username or password is incorrect, allowing an attacker to enumerate usernames by observing the application response. For example, if the username is incorrect, the application returns "User does not exist" with return code "10006", while if the password is incorrect, it returns "User does not exist or password is invalid" with return code "10013". This allows an attacker to determine if a username exists without knowing the password.

    Affected packages

    Package

    Name: github.com/IceWhaleTech/CasaOS-UserService

    Purl: pkg:golang/github.com/IceWhaleTech/CasaOS-UserService

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -0.4.8

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GO-2024-2668 | CVE-DB