#VU128265 Observable Response Discrepancy in Webauthn Framework - CVE-2024-39912

 

#VU128265 Observable Response Discrepancy in Webauthn Framework - CVE-2024-39912

Published: July 14, 2024 / Updated: April 28, 2026


Vulnerability identifier: #VU128265
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2024-39912
CWE-ID: CWE-204
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Webauthn Framework
Software vendor:
Web-Authentication

Description

The vulnerability allows a remote attacker to enumerate valid usernames.

The vulnerability exists due to observable response discrepancy in ProfileBasedRequestOptionsBuilder when handling assertion options requests with a supplied username. A remote attacker can send a specially crafted request to enumerate valid usernames.

The issue is exposed when WebAuthn is used as the first or only authentication method.


Remediation

Install security update from vendor's website.

External links