Incorrect User Management
CVE-2024-29296
Summary
A user enumeration vulnerability was found in Portainer Community Edition versions prior to 2.19.5, 2.20.0, and 2.20.1. This issue occurs during the user authentication process, where a difference in response time could allow a remote unauthenticated user to determine whether a username is valid.
- LOW
- NETWORK
- NONE
- UNCHANGED
- NONE
- NONE
- LOW
- NONE
CWE-286 - Incorrect User Management
The software does not properly manage a user within its environment.
References
Advisory Timeline
- Published