GHSA-r9x2-mg2v-mq96 · Severity: medium — The check user account lock states feature within the email OTP flow fails to validate user input...
The check user account lock states feature within the email OTP flow fails to validate user input, allowing an attacker to infer the existence of registered user accounts. The discovery of valid usernames can increase the risk of brute-force and social engineering attacks. Attackers can leverage this information to craft targeted phishing campaigns or other malicious activities aimed at tricking users into divulging sensitive data, potentially damaging the organization's reputation and leading to regulatory non-compliance and financial consequences.
Conclusion & alert: CVE-2024-0391 is rated Low Risk (23.5/100): CVSS Medium severity, with low exploitation likelihood (EPSS 0.02%). Mandatory action: Monitor for updates and reassess as exploit intelligence or EPSS changes.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-05-11 | — | 0.02% | — |
Full EPSS history (1 record total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 5.3 | 3.1 | MEDIUM |
|
3.9 | 1.4 | ed10eef1-636d-4fbe-9993-6890dfa878f8 |
| 4.3 | 3.1 | MEDIUM |
|
2.8 | 1.4 | [email protected] |
GHSA-r9x2-mg2v-mq96 · Severity: medium — The check user account lock states feature within the email OTP flow fails to validate user input...
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| wso2 | identity_server | >= 5.10.0, < 5.10.0.379 | cpe:2.3:a:wso2:identity_server:*:*:*:*:*:*:*:* |
| wso2 | identity_server | >= 5.11.0, < 5.11.0.426 | cpe:2.3:a:wso2:identity_server:*:*:*:*:*:*:*:* |
| wso2 | identity_server | >= 6.0.0, < 6.0.0.253 | cpe:2.3:a:wso2:identity_server:*:*:*:*:*:*:*:* |
| wso2 | identity_server | >= 6.1.0, < 6.1.0.254 | cpe:2.3:a:wso2:identity_server:*:*:*:*:*:*:*:* |
| wso2 | identity_server | >= 7.0.0, < 7.0.0.131 | cpe:2.3:a:wso2:identity_server:*:*:*:*:*:*:*:* |
| wso2 | identity_server_as_key_manager | >= 5.10.0, < 5.10.267 | cpe:2.3:a:wso2:identity_server_as_key_manager:*:*:*:*:*:*:*:* |
| wso2 | open_banking_iam | >= 2.0.0, < 2.0.0.318 | cpe:2.3:a:wso2:open_banking_iam:*:*:*:*:*:*:*:* |