PublicCVE

CVE-2024-38495

MEDIUM5.3JSON exportCreate alert

Description

A specific authentication strategy allows a malicious attacker to learn ids of all PAM users defined in its database.

CVSS breakdown

CVSS 4.0
Attack Vector
Adjacent
Attack Complexity
Low
Attack Requirements
None
Privileges Required
None
User Interaction
None
Confidentiality (Vulnerable System)
Low
Integrity (Vulnerable System)
None
Availability (Vulnerable System)
None
Confidentiality (Subsequent System)
None
Integrity (Subsequent System)
None
Availability (Subsequent System)
None