The "invite user" feature on the IntelOwl application is vulnerable to user enumeration. By attempting to invite a user and observing the different messages generated by the system, an attacker can determine if the username is valid and associated with an account on the system.
The bug is inherited from the library certego_saas which was patched in the 0.4.2 version.
The "invite user" feature on the IntelOwl application is vulnerable to user enumeration. By attempting to invite a user and observing the different messages generated by the system, an attacker can determine if the username is valid and associated with an account on the system.
The bug is inherited from the library certego_saas which was patched in the 0.4.2 version.