CVE-2024-54002 - CVE House
Back to Database
Status published Medium CVE-2024-54002

Dependency-Track allows enumeration of managed users via /api/v1/user/login endpoint

Vulnerability Description

Dependency-Track is a Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain. Performing a login request against the /api/v1/user/login endpoint with a username that exist in the system takes significantly longer than performing the same action with a username that is not known by the system. The observable difference in request duration can be leveraged by actors to enumerate valid names of managed users. LDAP and OpenID Connect users are not affected. The issue has been fixed in Dependency-Track 4.12.2.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-54002

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

DependencyTrack

View all reports →

Affected Software

dependency-track
Vulnerable Versions:
< 4.12.2

Timeline

Official Publish: December 4th, 2024
Last Modified: December 4th, 2024
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Weaknesses (CWE)