Cosmos Home Server User Existence Verification Vulnerability
Vulnerability
A vulnerability in Cosmos Home Server versions prior to 0.17.7 allows for user existence verification through error code analysis during the login process. This issue arises because the application does not properly obscure whether a username is registered in the database, creating a potential vector for user enumeration. Although the vulnerability's impact is considered low due to rate limiting that hinders scanning attempts, it still poses a risk by allowing targeted checks for user accounts, except for the 'admin' username, which is explicitly blocked.
Impact
Exploitation of this vulnerability could lead to unauthorized user enumeration, allowing an attacker to determine which usernames are registered in the application.
Remediation
Users can upgrade to Cosmos Home Server version 0.17.7 or later to address this vulnerability.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
