CVE-2019-9768: High severity thinkst vulnerability
Thinkst Canarytokens through commit hash 4e89ee0 (2019-03-01) relies on limited variation in size, metadata, and timestamp, which makes it easier for attackers to estimate whether a Word document contains a token.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-9768?
CVE-2019-9768 has a medium severity level due to its potential for information disclosure and token detection by attackers.
How do I fix CVE-2019-9768?
To mitigate CVE-2019-9768, upgrade to a version of Thinkst Canarytokens released after March 1, 2019.
What types of tokens are affected by CVE-2019-9768?
CVE-2019-9768 affects Word document tokens that rely on specific size and metadata characteristics.
Who is affected by CVE-2019-9768?
Any users running affected versions of Thinkst Canarytokens prior to version 2019-03-01 are vulnerable to CVE-2019-9768.
What is the impact of exploiting CVE-2019-9768?
Exploiting CVE-2019-9768 allows attackers to more easily identify and bypass Canarytokens within Word documents.