Improper permission enforcement in Checkmk versions 2.4.0 before 2.4.0p23, 2.3.0 before 2.3.0p43, and 2.2.0 (EOL) allows
Saleor is an e-commerce platform. From 2.10.0 to before 3.23.0a3, 3.22.47, 3.21.54, and 3.20.118, the requestEmailChange
MCO is vulnerable to User Enumeration through authentication-related functionalities. The application returns distinguis
Observable Response Discrepancy vulnerability in Erlang OTP ssh (ssh_sftpd module) allows an authenticated SFTP user to
An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. There is an ESEARCH cross-user content oracle. By u
A flaw has been found in projectsend up to r1945. This impacts an unknown function of the file includes/Classes/Auth.php
The login mechanism of Sage DPW 2021_06_004 displays distinct responses for valid and invalid usernames, allowing enumer
A vulnerability was found in Industrial Application Software IAS Canias ERP 8.03. The impacted element is the function d
SAP HANA Database (user self service tools) allows an unauthenticated user to send specially crafted requests that produ
A vulnerability was determined in automad up to 2.0.0-beta.32. This vulnerability affects the function requestPasswordRe
User enumeration in ESET Protect (on-prem) via Response Timing.
FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, the password reset conf
vantage6 is an open-source infrastructure for privacy preserving analysis. Versions prior to 5.0.0 provide an initial us
WPGraphQL provides a GraphQL API for WordPress sites. From 2.0.0 until 2.15.1, the deprecated user field on SendPassword
Lemmy is a link aggregator and forum for the fediverse. Prior to 0.19.19 and 1.0.0-beta.1, Lemmy's login endpoint in cra
Frappe is a full-stack web application framework. Prior to 15.115.0 and 16.27.0, the public request-data web form and Pe
User names used to access the web management interface are limited to the device identifier, which is a numerical ident
An unauthenticated remote attacker can enumerate valid user names from an unprotected endpoint.
CWE-204: Observable Response Discrepancy
Icinga 2 is an open source monitoring system. In Icinga 2 versions 2.4 through 2.15.0, filter expressions provided to th
This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create
ChurchCRM is an open-source church management system. Prior to version 6.5.0, the application echoes back plaintext pass
ImpactThe attacker can validate if a user exists by checking the time login returns. This timing difference can be used
An observable response discrepancy vulnerability [CWE-204] in FortiClientEMS 7.4.0, 7.2.0 through 7.2.4, 7.0 all version
Variable response times in the AWS Sign-in IAM user login flow allowed for the use of brute force enumeration techniques
IBM Control Center 6.2.1 and 6.3.1 could allow a remote attacker to enumerate usernames due to an observable discr
IBM Aspera Faspex 5.0.0 through 5.0.10 could disclose sensitive username information due to an observable response discr
pimcore/admin-ui-classic-bundle provides a Backend UI for Pimcore. In affected versions an error message discloses exist
SAP NetWeaver Server ABAP allows an unauthenticated attacker to exploit a vulnerability that causes the server to respon
A CWE-204 "Observable Response Discrepancy" in the login page in Q-Free MaxTime less than or equal to version 2.11.0 all
User Enumeration via Discrepancies in Error Messages in the Celk Sistemas Celk Saude v.3.1.252.1 password recovery funct
Zitadel is open-source identity infrastructure software. ZITADEL administrators can enable a setting called "Ignoring un
IBM TXSeries for Multiplatforms 9.1 and 11.1 could allow an attacker to enumerate usernames due to an observable login a
A vulnerability has been identified in Mendix Runtime V10 (All versions < V10.21.0), Mendix Runtime V10.12 (All versions
Shopware 6 is an open commerce platform based on Symfony Framework and Vue. Through the store-api it is possible as a at
A vulnerability in the login functionality of the web application of ctrlX OS allows a remote unauthenticated attacker t
Umbraco is a free and open source .NET content management system. Prior to versions 10.8.10 and 13.8.1, based on an anal
A vulnerability has been identified in Polarion V2310 (All versions), Polarion V2404 (All versions < V2404.2). The login
Observable Response Discrepancy vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enter
IBM Security Verify Access Appliance and Docker 10.0 through 10.0.8 could allow a remote attacker to enumerate usernames
For failed login attempts, the application returns different error messages depending on whether the login failed due to
For failed login attempts, the application returns different error messages depending on whether the login failed due to
Tuleap is an Open Source Suite created to facilitate management of software development and collaboration. In Tuleap Com
OPEXUS FOIAXpress Public Access Link (PAL) version v11.1.0 allows an unauthenticated, remote attacker to query the /App/
Saleor is an e-commerce platform. Starting in version 3.21.0 and prior to version 3.21.16, requesting certain fields in
Trivision NC-227WF firmware 5.80 (build 20141010) login mechanism reveals whether a username exists or not by returning
For failed login attempts, the application returns different error messages depending on whether the login failed due to
Icinga DB Web provides a graphical interface for Icinga monitoring. Before 1.1.4 and 1.2.3, an authorized user with acce
D-Link Nuclias Connect firmware versions <= 1.3.1.4 contain an observable response discrepancy vulnerability. The applic
D-Link Nuclias Connect firmware versions <= 1.3.1.4 contain an observable response discrepancy vulnerability. The applic
Frequently Asked Questions
What is CWE-204?
CWE-204 (CWE-204) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-204?
There are 181 CVE records associated with CWE-204 in our database. Of these, 2 are critical severity, 11 are high severity, and 140 are medium severity.
How can I protect against CWE-204 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-204 using AI-powered security agents.
Detect CWE-204 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-204 vulnerabilities across your infrastructure.
Get Started