{"id":"GO-2024-2614","summary":"Password brute force attack in github.com/IceWhaleTech/CasaOS-UserService","details":"The CasaOS web application does not have protection against password brute force attacks. An attacker can use a password brute force attack to find and gain full access to the server. This vulnerability allows attackers to get super user-level access over the server.","aliases":["CVE-2024-24767","GHSA-c69x-5xmw-v44x"],"modified":"2024-05-20T16:03:47Z","published":"2024-03-18T17:35:36Z","database_specific":{"review_status":"REVIEWED","url":"https://pkg.go.dev/vuln/GO-2024-2614"},"references":[{"type":"ADVISORY","url":"https://github.com/IceWhaleTech/CasaOS-UserService/security/advisories/GHSA-c69x-5xmw-v44x"},{"type":"FIX","url":"https://github.com/IceWhaleTech/CasaOS-UserService/commit/62006f61b55951048dbace4ebd9e483274838699"},{"type":"WEB","url":"https://github.com/IceWhaleTech/CasaOS-UserService/releases/tag/v0.4.7"}],"affected":[{"package":{"name":"github.com/IceWhaleTech/CasaOS-UserService","ecosystem":"Go","purl":"pkg:golang/github.com/IceWhaleTech/CasaOS-UserService"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0.4.4-3-alpha1"},{"fixed":"0.4.7"}]}],"ecosystem_specific":{"imports":[{"path":"github.com/IceWhaleTech/CasaOS-UserService/route/v1","symbols":["PostUserLogin"]}]},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2024-2614.json"}}],"schema_version":"1.7.3","credits":[{"name":"DrDark1999"}]}