cve/2024/CVE-2024-11084.md
2025-09-29 16:08:36 +00:00

18 lines
672 B
Markdown

### [CVE-2024-11084](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-11084)
![](https://img.shields.io/static/v1?label=Product&message=Helix%20ALM&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=0%3C%202025.1%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-203%20Observable%20Discrepancy&color=brighgreen)
### Description
Helix ALM prior to 2025.1 returns distinct error responses during authentication, allowing an attacker to determine whether a username exists.
### POC
#### Reference
- https://portal.perforce.com/s/detail/a91PA000001SeWbYAK
#### Github
No PoCs found on GitHub currently.