An issue was discovered in Kurmi Provisioning Suite before 7.9.0.35, 7.10.x through 7.10.0.18, and 7.11.x through 7.11.0.15. An Observable Response Discrepancy vulnerability in the sendPasswordReinitLink action of the unlogged.do page allows remote attackers to test whether a username is valid or not. This allows confirmation of valid usernames.
References
Configurations
No configuration.
History
31 Dec 2024, 19:15
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
|
CWE | CWE-203 | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.3 |
27 Dec 2024, 20:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-12-27 20:15
Updated : 2024-12-31 19:15
NVD link : CVE-2024-54454
Mitre link : CVE-2024-54454
CVE.ORG link : CVE-2024-54454
JSON object : View
Products Affected
No product.
CWE
CWE-203
Observable Discrepancy