CVE-2024-0391: CWE-204 Observable response discrepancy in WSO2 WSO2 Identity Server
CVE-2024-0391 is a medium severity vulnerability in WSO2 Identity Server versions 5.10.0 through 7.0.0. It involves an observable response discrepancy in the email OTP flow's user account lock state check, which fails to properly validate user input. This flaw allows an attacker to determine whether specific usernames are registered in the system. Such information disclosure can facilitate brute-force and social engineering attacks, increasing risks to user data and organizational security.
AI Analysis
Technical Summary
The vulnerability CVE-2024-0391 in WSO2 Identity Server arises from improper validation in the email OTP flow's check for user account lock states. This leads to observable differences in responses that enable attackers to confirm the existence of user accounts. The affected versions include 5.10.0, 5.11.0, 6.0.0, 6.1.0, and 7.0.0. The CVSS 3.1 base score is 5.3 (medium severity), reflecting network attack vector, low complexity, no privileges or user interaction required, and limited confidentiality impact. No official patch or remediation guidance is currently documented, and no known exploits are reported in the wild.
Potential Impact
An attacker can leverage this vulnerability to enumerate valid usernames by observing response discrepancies during the email OTP flow. This information disclosure increases the risk of targeted brute-force attacks and social engineering campaigns such as phishing. While the vulnerability does not directly allow data modification or denial of service, the indirect impact includes potential compromise of user accounts and reputational damage to the organization.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since no official fix or temporary workaround is documented, organizations should monitor WSO2 advisories for updates. Until a patch is available, consider restricting access to the affected functionality or implementing additional rate limiting and monitoring to detect enumeration attempts.
CVE-2024-0391: CWE-204 Observable response discrepancy in WSO2 WSO2 Identity Server
Description
CVE-2024-0391 is a medium severity vulnerability in WSO2 Identity Server versions 5.10.0 through 7.0.0. It involves an observable response discrepancy in the email OTP flow's user account lock state check, which fails to properly validate user input. This flaw allows an attacker to determine whether specific usernames are registered in the system. Such information disclosure can facilitate brute-force and social engineering attacks, increasing risks to user data and organizational security.
CVSS v3.1
Score 5.3medium
Affected software
pkg:maven/org.wso2.identity.server/wso2-identity-serverRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability CVE-2024-0391 in WSO2 Identity Server arises from improper validation in the email OTP flow's check for user account lock states. This leads to observable differences in responses that enable attackers to confirm the existence of user accounts. The affected versions include 5.10.0, 5.11.0, 6.0.0, 6.1.0, and 7.0.0. The CVSS 3.1 base score is 5.3 (medium severity), reflecting network attack vector, low complexity, no privileges or user interaction required, and limited confidentiality impact. No official patch or remediation guidance is currently documented, and no known exploits are reported in the wild.
Potential Impact
An attacker can leverage this vulnerability to enumerate valid usernames by observing response discrepancies during the email OTP flow. This information disclosure increases the risk of targeted brute-force attacks and social engineering campaigns such as phishing. While the vulnerability does not directly allow data modification or denial of service, the indirect impact includes potential compromise of user accounts and reputational damage to the organization.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since no official fix or temporary workaround is documented, organizations should monitor WSO2 advisories for updates. Until a patch is available, consider restricting access to the affected functionality or implementing additional rate limiting and monitoring to detect enumeration attempts.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- WSO2
- Date Reserved
- 2024-01-10T09:02:14.122Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a01aa21cbff5d8610f2b6e8
Added to database: 05/11/2026, 10:06:25 UTC
Last enriched: 05/18/2026, 10:48:32 UTC
Last updated: 07/31/2026, 19:22:51 UTC
Views: 83
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.