PT-2024-36009 · Unknown · Dependency-Track

·

CVE-2024-54002

·

Published

2024-12-04

·

Updated

2024-12-05

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Dependency-Track versions prior to 4.12.2
Description: The issue allows actors to enumerate valid names of managed users by leveraging the observable difference in request duration when performing a login request against the "/api/v1/user/login" endpoint with a username that exists in the system versus one that does not. This can be done by measuring the time it takes to process a login request with an existing username versus a non-existing one. LDAP and OpenID Connect users are not affected.
Recommendations: For versions prior to 4.12.2, update to Dependency-Track 4.12.2 to resolve the issue. As a temporary workaround, consider restricting access to the "/api/v1/user/login" endpoint to minimize the risk of exploitation. Avoid using this endpoint for login requests until the issue is resolved.

Exploit

Fix

Side Channel Attack

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-54002
GHSA-9W3M-HM36-W32W

Affected Products

Dependency-Track