
Cloud Vulnerability DB
A community-led vulnerabilities database
A critical security vulnerability (CVE-2024-24767) was discovered in CasaOS-UserService affecting versions up to v0.4.4.3. The vulnerability stems from improper restriction of excessive authentication attempts, which allows attackers to perform password brute force attacks against the system. The issue was disclosed and patched in version 0.4.7, released on March 6, 2024 (GitHub Advisory).
The vulnerability is characterized by a lack of login attempt controls in the web application, enabling unrestricted password brute force attacks. Testing demonstrated that an attacker could perform 271 login attempts within 56 seconds, with failed attempts receiving a 400 Bad Request status code and successful attempts receiving a 200 OK response. The vulnerability has been assigned a CVSS v3.1 base score of 7.3 (High), with attack vector: Network, attack complexity: Low, privileges required: None, user interaction: None, scope: Unchanged, and Low impact on confidentiality, integrity, and availability (GitHub Advisory).
The vulnerability enables attackers to gain super user-level access to the server through successful brute force attacks. This could lead to complete system compromise, as demonstrated through proof-of-concept testing with over 3,400 login attempts (GitHub Advisory).
The vulnerability is highly exploitable as it requires no special privileges or user interaction. Proof-of-concept testing has shown that attackers can automate login attempts using common proxy tools like Burp Suite, with the ability to test hundreds of passwords within minutes (GitHub Advisory).
The vulnerability has been patched in CasaOS-UserService version 0.4.7. The fix implements a rate-limiting mechanism that restricts login attempts to 5 per minute. It is recommended to implement IP-based blocking for 30 seconds after 5 failed login attempts to prevent brute force attacks (GitHub Release, GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."