First published: Tue Mar 28 2017(Updated: )
Revive Adserver before 3.2.3 suffers from session fixation, by allowing arbitrary session identifiers to be forced and, at the same time, by not invalidating the existing session upon a successful authentication. Under some circumstances, that could have been an opportunity for an attacker to steal an authenticated session.
Credit: support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
Revive Adserver | <=3.2.2 |
https://github.com/revive-adserver/revive-adserver/commit/4910365631eabbb208961c36149f41cc8159fb39
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-9125 is considered a medium severity vulnerability due to its potential to allow session fixation attacks.
To fix CVE-2016-9125, upgrade Revive Adserver to version 3.2.3 or later.
CVE-2016-9125 affects Revive Adserver versions prior to 3.2.3.
CVE-2016-9125 is a session fixation vulnerability that allows attackers to force arbitrary session identifiers.
Yes, CVE-2016-9125 can potentially allow attackers to steal session tokens and gain unauthorized access.