Skip to main content

Incorrect User Management

CVE-2024-29296

Severity Medium
Score 5.3/10

Summary

A user enumeration vulnerability was found in Portainer Community Edition versions prior to 2.19.5, 2.20.0, and 2.20.1. This issue occurs during the user authentication process, where a difference in response time could allow a remote unauthenticated user to determine whether a username is valid.

  • LOW
  • NETWORK
  • NONE
  • UNCHANGED
  • NONE
  • NONE
  • LOW
  • NONE

CWE-286 - Incorrect User Management

The software does not properly manage a user within its environment.

Advisory Timeline

  • Published