CVE-2024-54454

An issue was discovered in Kurmi Provisioning Suite before 7.9.0.35, 7.10.x through 7.10.0.18, and 7.11.x through 7.11.0.15. An Observable Response Discrepancy vulnerability in the sendPasswordReinitLink action of the unlogged.do page allows remote attackers to test whether a username is valid or not. This allows confirmation of valid usernames.
Configurations

No configuration.

History

31 Dec 2024, 19:15

Type Values Removed Values Added
Summary
  • (es) Se descubrió un problema en Kurmi Provisioning Suite anterior a 7.9.0.35, 7.10.x a 7.10.0.18 y 7.11.x a 7.11.0.15. Una vulnerabilidad de discrepancia de respuesta observable en la acción sendPasswordReinitLink de la página unlogged.do permite a atacantes remotos probar si un nombre de usuario es válido o no. Esto permite el commit de nombres de usuario válidos.
CWE CWE-203
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.3

27 Dec 2024, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-12-27 20:15

Updated : 2024-12-31 19:15


NVD link : CVE-2024-54454

Mitre link : CVE-2024-54454

CVE.ORG link : CVE-2024-54454


JSON object : View

Products Affected

No product.

CWE
CWE-203

Observable Discrepancy