CVE-2024-25651: Medium severity delinea pam secret server vulnerability
User enumeration can occur in the Authentication REST API in Delinea PAM Secret Server 11.4. This allows a remote attacker to determine whether a user is valid because of a difference in responses from the /oauth2/token endpoint.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-25651?
CVE-2024-25651 is classified with a high severity due to its potential to allow user enumeration.
How does CVE-2024-25651 affect user authentication?
CVE-2024-25651 allows remote attackers to determine valid user accounts based on differing responses from the authentication API.
What version of Delinea PAM Secret Server is affected by CVE-2024-25651?
CVE-2024-25651 affects Delinea PAM Secret Server version 11.4.
How can I mitigate CVE-2024-25651 in my application?
Mitigation for CVE-2024-25651 can involve implementing rate limiting and response time normalization for authentication endpoints.
Is there an available patch for CVE-2024-25651?
As of now, there is no specific patch released for CVE-2024-25651, but it's recommended to monitor official updates from Delinea.