CyberRota Analysis
AI-GeneratedAn information disclosure vulnerability exists in Capgo versions prior to 12.128.2, specifically in the unauthenticated /private/sso/check-domain endpoint, which exposes internal org_id and provider_id values. This flaw allows attackers to enumerate email domains, potentially mapping them to organization UUIDs and SSO provider identifiers, facilitating reconnaissance against Capgo tenants. Organizations using Capgo should prioritize patching this vulnerability to mitigate the risk of unauthorized information exposure.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Capgo before 12.128.2 contains an information disclosure vulnerability in the unauthenticated /private/sso/check-domain endpoint that returns internal org_id and provider_id values. Attackers can enumerate email domains to build mappings of domains to organization UUIDs and SSO provider identifiers, enabling reconnaissance against Capgo tenants.