{"id":"CVE-2024-29296","aliases":["GHSA-87x6-8m9v-g8c2"],"title":"Portainer CE allows username enumeration through authentication response timing","summary":"Portainer CE allows username enumeration through authentication response timing","severity":"medium","cvss":5.3,"cwe":["CWE-286"],"vendor":"portainer","product":"github.com/portainer/portainer","ecosystem":"go","affected":["github.com/portainer/portainer < 0.6.1-0.20240417040827-48bc7d0d92f0"],"patched":["github.com/portainer/portainer 0.6.1-0.20240417040827-48bc7d0d92f0"],"published":"2024-04-10","updated":"2026-09-30","sourceUpdated":"2026-09-30T23:23:55Z","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-87x6-8m9v-g8c2","references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2024-29296"},{"url":"https://github.com/ThaySolis/CVE-2024-29296"},{"url":"https://github.com/portainer/portainer/issues/11736"},{"url":"https://github.com/portainer/portainer/pull/11589"},{"url":"https://github.com/portainer/portainer/commit/48bc7d0d92f038e04a72c1e0585bc325eb63a9e6"},{"url":"https://github.com/portainer/portainer/releases/tag/2.19.5"},{"url":"https://github.com/portainer/portainer/releases/tag/2.20.2"},{"url":"https://github.com/advisories/GHSA-87x6-8m9v-g8c2"}],"tags":["ghsa","go","exploit-available"],"epss":0.01252,"epssPercentile":0.68319,"exploits":{"github":2,"githubRepos":["https://github.com/ThaySolis/CVE-2024-29296","https://github.com/Lavender-exe/CVE-2024-29296-PoC"],"checkedAt":"2026-09-30T23:30:07.510Z"},"exploitAvailable":true,"ingestedAt":"2026-09-30T23:29:32.584Z","slug":"CVE-2024-29296","body":"## Overview\n\nA user enumeration vulnerability was found in Portainer CE 2.19.4. This issue occurs during user authentication process, where a difference in response time could allow a remote unauthenticated user to determine if a username is valid or not.\n\n## Affected packages\n\n- `github.com/portainer/portainer < 0.6.1-0.20240417040827-48bc7d0d92f0`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `github.com/portainer/portainer 0.6.1-0.20240417040827-48bc7d0d92f0`","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":29.2,"likelihood":0.3,"exploitation":12,"ransomware":0},"changes":[]}