CWE-204

Observable Response Discrepancy

Parent: CWE-203 - Observable Discrepancy

The product provides different responses to incoming requests in a way that reveals internal state information to an unauthorized actor outside of the intended control sphere.

167 vulnerabilities with CWE-204
CVE-2024-13198 LOW
Langhsu Mblog Blog System 3.5.0 - Info Disclosure
CVSS 3.7
CVE-2024-13028 LOW
Antabot White-Jotter <0.2.2 - Info Disclosure
CVSS 3.7
CVE-2024-12663 LOW
Mee-Admin <= 1.6 - Observable Response Discrepancy via Login Username Parameter
CVSS 3.7
CVE-2024-47129 MEDIUM
goTenna Pro App < 1.6.1 and < 2.0.3 - Observable Response Discrepancy via Broadcast Frame Length
CVSS 4.3
CVE-2024-41715 MEDIUM
goTenna Pro ATAK Plugin < 2.0.7 - Observable Response Discrepancy via Broadcast Frame Length
CVSS 4.3
CVE-2024-8651 MEDIUM
NetCat CMS <6.4.0.24248 - Info Disclosure
CVSS 5.3
CVE-2024-34336 MEDIUM
ORDAT FOSS-Online <2.24.01 - Info Disclosure
CVSS 5.3
CVE-2024-42343 MEDIUM
Loway QueueMetrics 17.06.1-24.05.5 - Observable Response Discrepancy
CVSS 5.3
CVE-2024-38431 MEDIUM
Matrix Tafnit < 8.4.202 - Observable Response Discrepancy
CVSS 5.3
CVE-2024-40627 MEDIUM
fastapi-opa < 2.0.1 - Unauthenticated Information Disclosure via OPTIONS Request Bypass
CVSS 5.8
CVE-2024-39912 MEDIUM
web-auth/webauthn-lib - Info Disclosure
CVSS 5.3
CVE-2024-39211 MEDIUM
Kaiten 57.128.8 - User Account Enumeration via Login Response Discrepancy
CVSS 5.3
CVE-2024-36996 MEDIUM
Splunk Enterprise <9.2.2, <9.1.5, <9.0.10 & Splunk Cloud <9.1.2312.109 User Enumeration via SAML
CVSS 5.3
CVE-2024-38322 MEDIUM
IBM Storage Defender - Resiliency Service <2.0.5 - Info Disclosure
CVSS 5.3
CVE-2024-6056 LOW
nasirkhan/laravel_starter < 11.8.0 - Observable Response Discrepancy via Password Reset Email Parameter
CVSS 3.7
CVE-2024-31870 LOW
IBM Db2 for i <7.6 - Info Disclosure
CVSS 3.3
CVE-2024-33856 MEDIUM
Logpoint SIEM < 7.4.0 - Username Enumeration via Forgot Password Endpoint Response Timing
CVSS 5.3
CVE-2024-28232 MEDIUM
IceWhaleTech CasaOS-UserService >=0.4.7 <0.4.8 - Username Enumeration via Login Page
CVSS 6.2
CVE-2024-28868 LOW
Umbraco CMS 10.0.0-10.8.4 - User Enumeration via Native Login Screen
CVSS 3.7
CVE-2024-1145 MEDIUM
Devklan's Alma Blog <2.1.10 - Info Disclosure
CVSS 5.3
CVE-2024-2482 LOW
Surya2Developer Hostel Management Service 1.0 - Info Disclosure
CVSS 3.7
CVE-2024-24766 MEDIUM
CasaOS-UserService 0.4.4.3-0.4.6 - Username Enumeration via Login Error Messages
CVSS 6.2
CVE-2024-25146 MEDIUM
Liferay Portal/DXP - Info Disclosure
CVSS 5.3
CVE-2023-37413 MEDIUM
IBM Aspera Faspex 5.0.0-5.0.10 - Username Information Disclosure via Observable Response Discrepancy
CVSS 5.3
CVE-2023-47159 MEDIUM
IBM Sterling File Gateway 6.0.0.0-6.1.2.5 & 6.2.0.0-6.2.0.1 Username Enumeration via Response Discrepancy
CVSS 4.3
Details
Vulnerabilities 167