CVE-2017-5831: Medium severity revive-adserver Revive Adserver vulnerability
Session fixation vulnerability in the forgot password mechanism in Revive Adserver before 4.0.1, when setting a new password, allows remote attackers to hijack web sessions via the session ID.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Revive Adserverto a version that resolves this vulnerability.Fixed in 4.0.1
Event History
Frequently Asked Questions
What is the severity of CVE-2017-5831?
CVE-2017-5831 is considered a high severity vulnerability as it allows attackers to hijack user sessions.
How do I fix CVE-2017-5831?
To fix CVE-2017-5831, upgrade your Revive Adserver to version 4.0.1 or later.
What type of attack does CVE-2017-5831 facilitate?
CVE-2017-5831 facilitates session fixation attacks, allowing remote attackers to take control of user sessions.
Which versions of Revive Adserver are affected by CVE-2017-5831?
CVE-2017-5831 affects all versions of Revive Adserver prior to 4.0.1.
What can an attacker do with CVE-2017-5831?
An attacker exploiting CVE-2017-5831 can hijack a user's web session through manipulation of the session ID.