User enumeration can occur in the Authentication REST API...
Moderate severity
Unreviewed
Published
Mar 14, 2024
to the GitHub Advisory Database
•
Updated Aug 22, 2024
Description
Published by the National Vulnerability Database
Mar 14, 2024
Published to the GitHub Advisory Database
Mar 14, 2024
Last updated
Aug 22, 2024
User enumeration can occur in the Authentication REST API in Delinea PAM Secret Server 11.4. This allows a remote attacker to determine whether a user is valid because of a difference in responses from the /oauth2/token endpoint.
References