CasaOS-UserService provides user management functionalities to CasaOS. Starting in version 0.4.4.3 and prior to version 0.4.7, CasaOS doesn't defend against password brute force attacks, which leads to having full access to the server. The web application lacks control over the login attempts. This vulnerability allows attackers to get super user-level access over the server. Version 0.4.7 contains a patch for this issue.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-0897 | CasaOS-UserService provides user management functionalities to CasaOS. Starting in version 0.4.4.3 and prior to version 0.4.7, CasaOS doesn't defend against password brute force attacks, which leads to having full access to the server. The web application lacks control over the login attempts. This vulnerability allows attackers to get super user-level access over the server. Version 0.4.7 contains a patch for this issue. |
Github GHSA |
GHSA-c69x-5xmw-v44x | CasaOS Improper Restriction of Excessive Authentication Attempts vulnerability |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 26 Feb 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Icewhale
Icewhale casaos |
|
| CPEs | cpe:2.3:o:icewhale:casaos:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Icewhale
Icewhale casaos |
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-28T17:53:11.773Z
Reserved: 2024-01-29T20:51:26.013Z
Link: CVE-2024-24767
Updated: 2024-08-01T23:28:11.820Z
Status : Analyzed
Published: 2024-03-06T18:15:46.983
Modified: 2025-04-10T20:31:56.250
Link: CVE-2024-24767
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA