An issue was discovered in Kurmi Provisioning Suite before 7.9.0.35, 7.10.x through 7.10.0.18, and 7.11.x through 7.11.0.15. An Observable Response Discrepancy vulnerability in the sendPasswordReinitLink action of the unlogged.do page allows remote attackers to test whether a username is valid or not. This allows confirmation of valid usernames.
Metrics
Affected Vendors & Products
References
History
Tue, 31 Dec 2024 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-203 | |
Metrics |
cvssV3_1
|
Fri, 27 Dec 2024 20:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An issue was discovered in Kurmi Provisioning Suite before 7.9.0.35, 7.10.x through 7.10.0.18, and 7.11.x through 7.11.0.15. An Observable Response Discrepancy vulnerability in the sendPasswordReinitLink action of the unlogged.do page allows remote attackers to test whether a username is valid or not. This allows confirmation of valid usernames. | |
References |
|
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2024-12-27T00:00:00
Updated: 2024-12-31T18:35:45.374Z
Reserved: 2024-12-02T00:00:00
Link: CVE-2024-54454
Vulnrichment
Updated: 2024-12-31T18:35:37.486Z
NVD
Status : Awaiting Analysis
Published: 2024-12-27T20:15:23.777
Modified: 2024-12-31T19:15:47.310
Link: CVE-2024-54454
Redhat
No data.