ZeroHour

CVE-2024-28232

PoC
CVSS 3.1
7.5 high
EPSS
<1%p48
Published
()
Modified
Description

Go package IceWhaleTech/CasaOS-UserService provides user management functionalities to CasaOS. The Casa OS Login page has disclosed the username enumeration vulnerability in the login page which was patched in version 0.4.7. This issue in CVE-2024-28232 has been patched in version 0.4.8 but that version has not yet been uploaded to Go's package manager.

Vendors
icewhale
Products
casaos-userservice
Weakness
CWE-204
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.