CVE-2024-52043: User enumeration in HubHub
Published Nov 6, 2024
·Updated
Generation of Error Message Containing Sensitive Information in HumHub GmbH & Co. KG - HumHub on Linux allows: Excavation (user enumeration).This issue affects all released HumHub versions: through 1.16.2.
Affected Software
1 affected component
Humhub Humhub<=1.16.2
Event History
Nov 6, 2024
CVE Published
via MITRE·07:51 AM
Data Sourced
via MITRE·07:51 AM
DescriptionWeakness
Data Sourced
via NVD·08:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-52043?
CVE-2024-52043 is considered a medium severity vulnerability due to its potential for user enumeration.
2
How do I fix CVE-2024-52043?
To fix CVE-2024-52043, update your HumHub installation to version 1.16.3 or later.
3
Which versions of HumHub are affected by CVE-2024-52043?
CVE-2024-52043 affects all released HumHub versions up to and including 1.16.2.
4
What type of vulnerability is CVE-2024-52043?
CVE-2024-52043 is a vulnerability that involves the generation of error messages containing sensitive information.
5
What is the impact of CVE-2024-52043?
The impact of CVE-2024-52043 allows attackers to perform excavation or user enumeration against the affected HumHub installations.