---
id: CVE-2024-29296
aliases:
  - GHSA-87x6-8m9v-g8c2
title: >-
  Portainer CE allows username enumeration through authentication response
  timing
summary: >-
  Portainer CE allows username enumeration through authentication response
  timing
severity: medium
cvss: 5.3
cwe:
  - CWE-286
vendor: portainer
product: github.com/portainer/portainer
ecosystem: go
affected:
  - github.com/portainer/portainer < 0.6.1-0.20240417040827-48bc7d0d92f0
patched:
  - github.com/portainer/portainer 0.6.1-0.20240417040827-48bc7d0d92f0
published: '2024-04-10'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T23:23:55Z'
source: GHSA
sourceUrl: 'https://github.com/advisories/GHSA-87x6-8m9v-g8c2'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2024-29296'
  - url: 'https://github.com/ThaySolis/CVE-2024-29296'
  - url: 'https://github.com/portainer/portainer/issues/11736'
  - url: 'https://github.com/portainer/portainer/pull/11589'
  - url: >-
      https://github.com/portainer/portainer/commit/48bc7d0d92f038e04a72c1e0585bc325eb63a9e6
  - url: 'https://github.com/portainer/portainer/releases/tag/2.19.5'
  - url: 'https://github.com/portainer/portainer/releases/tag/2.20.2'
  - url: 'https://github.com/advisories/GHSA-87x6-8m9v-g8c2'
tags:
  - ghsa
  - go
  - exploit-available
epss: 0.01252
epssPercentile: 0.68319
exploits:
  github: 2
  githubRepos:
    - 'https://github.com/ThaySolis/CVE-2024-29296'
    - 'https://github.com/Lavender-exe/CVE-2024-29296-PoC'
  checkedAt: '2026-09-30T23:30:07.510Z'
exploitAvailable: true
ingestedAt: '2026-09-30T23:29:32.584Z'
---

## Overview

A user enumeration vulnerability was found in Portainer CE 2.19.4. This issue occurs during user authentication process, where a difference in response time could allow a remote unauthenticated user to determine if a username is valid or not.

## Affected packages

- `github.com/portainer/portainer < 0.6.1-0.20240417040827-48bc7d0d92f0`

## Remediation

Upgrade to a patched release:

- `github.com/portainer/portainer 0.6.1-0.20240417040827-48bc7d0d92f0`
