{"id":"GHSA-hcw2-2r9c-gc6p","summary":"CasaOS Username Enumeration - Bypass of CVE-2024-24766","details":"### Summary\n\nThe Casa OS Login page has disclosed the username enumeration vulnerability in the login page which was patched in `CasaOS  v0.4.7`.\n\n### Details\n\nIt is observed that the attacker can enumerate the CasaOS username using the application response. If the username is incorrect the application gives the error \"**User does not exist**\" with success code \"**10006**\", If the password is incorrect the application gives the error \"**User does not exist or password is invalid**\" with success code \"**10013**\".\n\n### PoC\n\n1. If the Username is invalid application gives \"User does not exist\" with success code \"**10006**\".\n\n![1](https://github.com/IceWhaleTech/CasaOS-UserService/assets/63414468/a6eb4321-b2f3-4fba-aa8e-e1d0fbf58187)\n\n2. If the Password is invalid application gives  \"**User does not exist or password is invalid**\" with success code \"**10013**\".\n\n![2](https://github.com/IceWhaleTech/CasaOS-UserService/assets/63414468/126eff54-eeb0-4ee6-bc46-695376b5e5cd)\n\n\n### Impact\n\nUsing this error attacker can enumerate the username of CasaOS.\n\n### The logic behind the issue\n\nThe logic behind the issue\nIf the username is incorrect, then throw an error  \"**User does not exist**\" with success code \"**10006**\", else throw an error \"**User does not exist or password is invalid**\" with success code \"**10013**\".\n\nThis condition can be vice versa like:\n\nIf the password is incorrect, then throw an error \"**User does not exist or password is invalid**\" with success code \"**10013**\", else throw an error  \"**User does not exist**\" with success code \"**10006**\".\n\n### Mitigation\nSince this is the condition we have to implement a single error which can be \"**Username/Password is Incorrect!!!**\" with single success code.","aliases":["CVE-2024-28232","GO-2024-2668"],"modified":"2026-02-04T03:47:27.000884Z","published":"2024-04-01T15:48:15Z","related":["CVE-2024-24766"],"database_specific":{"github_reviewed_at":"2024-04-01T15:48:15Z","nvd_published_at":"2024-04-01T17:15:45Z","cwe_ids":["CWE-204"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/IceWhaleTech/CasaOS-UserService/security/advisories/GHSA-hcw2-2r9c-gc6p"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-28232"},{"type":"WEB","url":"https://github.com/IceWhaleTech/CasaOS-UserService/commit/dd927fe1c805e53790f73cfe10c7a4ded3bc5bdb"},{"type":"PACKAGE","url":"https://github.com/IceWhaleTech/CasaOS-UserService"}],"affected":[{"package":{"name":"github.com/IceWhaleTech/CasaOS-UserService","ecosystem":"Go","purl":"pkg:golang/github.com/IceWhaleTech/CasaOS-UserService"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0.4.7"},{"fixed":"0.4.8"}]}],"versions":["0.4.7"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/04/GHSA-hcw2-2r9c-gc6p/GHSA-hcw2-2r9c-gc6p.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}