← Back

CVE-2024-28232

nvd nist
Published: Apr 1, 2024Modified: Jun 24, 2025

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

Go package IceWhaleTech/CasaOS-UserService provides user management functionalities to CasaOS. The Casa OS Login page has disclosed the username enumeration vulnerability in the login page which was patched in version 0.4.7. This issue in CVE-2024-28232 has been patched in version 0.4.8 but that version has not yet been uploaded to Go's package manager.

Affected (1)

1 product
Casaos Userservice
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 0.4.7

Timeline

No history available yet.