PT-2024-36009 · Unknown · Dependency-Track

Hannes Michel

·

Published

2024-12-04

·

Updated

2024-12-05

·

CVE-2024-54002

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Dependency-Track versions prior to 4.12.2
Description: The issue allows actors to enumerate valid names of managed users by leveraging the observable difference in request duration when performing a login request against the "/api/v1/user/login" endpoint with a username that exists in the system versus one that does not. This can be done by measuring the time it takes to process a login request with an existing username versus a non-existing one. LDAP and OpenID Connect users are not affected.
Recommendations: For versions prior to 4.12.2, update to Dependency-Track 4.12.2 to resolve the issue. As a temporary workaround, consider restricting access to the "/api/v1/user/login" endpoint to minimize the risk of exploitation. Avoid using this endpoint for login requests until the issue is resolved.

Exploit

Fix

Side Channel Attack

Weakness Enumeration

Related Identifiers

CVE-2024-54002
GHSA-9W3M-HM36-W32W

Affected Products

Dependency-Track