Vulnerability GHSA-87x6-8m9v-g8c2
Medium Risk
MEDIUM RISK
CVSS Score: 5.3
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
2 years ago
April 10, 2024 at 03:30 PM UTC
Portainer CE allows username enumeration through authentication response timing
v0.6.0
v0.6.0
Summary
Portainer CE allows username enumeration through authentication response timing
Details
A user enumeration vulnerability was found in Portainer CE 2.19.4. This issue occurs during user authentication process, where a difference in response time could allow a remote unauthenticated user to determine if a username is valid or not.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Unknown
28 days ago
Portainer has Unauthenticated Restore Endpoint that Allows Admin Takeover on Uninitialized Instances in github.com/portainer/portainer
v0.6.0 - v0.10.1 GO-2026-6324
v0.6.0 - v0.10.1 GO-2026-6324
Medium Risk
1 month ago
Portainer has Unauthenticated Restore Endpoint that Allows Admin Takeover on Uninitialized Instances
>=2.39.0 <2.39.4, >=2.40.0 <2.43.0 GHSA-x626-fcwx-f5pc
>=2.39.0 <2.39.4, >=2.40.0 <2.43.0 GHSA-x626-fcwx-f5pc
Unknown
2 months ago
Portainer has a path traversal in backup archive extraction that allows arbitrary file write in github.com/portainer/portainer
v0.6.0 - v0.10.1 GO-2026-5498
v0.6.0 - v0.10.1 GO-2026-5498
Unknown
3 months ago
Portainer Has an Arbitrary File Read via Git Symlink Injection in Stack Auto-Update in github.com/portainer/portainer
v0.6.0 - v0.10.1 GO-2026-5633
v0.6.0 - v0.10.1 GO-2026-5633
Unknown
3 months ago
Portainer missing authorization on Docker plugin endpoints, which allows host RCE in github.com/portainer/portainer
v0.6.0 - v0.10.1 GO-2026-5639
v0.6.0 - v0.10.1 GO-2026-5639
Impacted packages
Timeline
Published
2 years ago
April 10, 2024 at 03:30 PM UTC
Last Modified
7 hours ago
September 30, 2026 at 11:30 PM UTC