VulnerabilityModified
CVE-2016-9129
Revive Adserver before 3.2.3 suffers from Information Exposure Through Discrepancy.
MEDIUM 5.3EPSS 1.43%
Does this matter?
Lower severity and a low EPSS score (1.43%). Track it; it rarely justifies an emergency change on its own.
Description
Revive Adserver before 3.2.3 suffers from Information Exposure Through Discrepancy. It is possible to check whether or not an email address was associated to one or more user accounts on a target Revive Adserver instance by examining the message printed by the password recovery system. Such information cannot however be used directly to log in to the system, which requires a username.
- CVSS 3.0
- 5.3 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 1.43% probability · 72th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-203, CWE-200
- Affected
- revive-adserver/revive adserver
- Source
- support@hackerone.com
References
- https://github.com/revive-adserver/revive-adserver/commit/38223a841190bebd7a137c7bed84fbbcb2b0c2a5Issue Tracking, Patch, Third Party Advisory
- https://hackerone.com/reports/98612Permissions Required
- https://www.revive-adserver.com/security/revive-sa-2016-001/Patch, Vendor Advisory
- https://github.com/revive-adserver/revive-adserver/commit/38223a841190bebd7a137c7bed84fbbcb2b0c2a5Issue Tracking, Patch, Third Party Advisory
- https://hackerone.com/reports/98612Permissions Required
- https://www.revive-adserver.com/security/revive-sa-2016-001/Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.