CVE-2019-14537: Critical severity yourls vulnerability
Published Aug 7, 2019
·Updated
YOURLS through 1.7.3 is affected by a type juggling vulnerability in the api component that can result in login bypass.
Affected Software
1 affected component
Yourls Yourls<=1.7.3
Remediation
Patch Available
Patch Available
Event History
Aug 7, 2019
CVE Published
via MITRE·04:43 PM
Data Sourced
via MITRE·04:43 PM
Description
Frequently Asked Questions
1
What is CVE-2019-14537?
CVE-2019-14537 is a type juggling vulnerability in the YOURLS through 1.7.3 API component that can result in login bypass.
2
How severe is CVE-2019-14537?
CVE-2019-14537 has a severity score of 9.8, which is considered critical.
3
What software versions are affected by CVE-2019-14537?
YOURLS versions up to and including 1.7.3 are affected by CVE-2019-14537.
4
How can I fix CVE-2019-14537?
To fix CVE-2019-14537, you should update YOURLS to a version higher than 1.7.3.
5
Where can I find more information about CVE-2019-14537?
You can find more information about CVE-2019-14537 on the following references: [GitHub](https://github.com/Wocanilo/CVE-2019-14537), [YOURLS Commits](https://github.com/YOURLS/YOURLS/commits/master), [YOURLS Pull Request](https://github.com/YOURLS/YOURLS/pull/2542).