CVE-2021-22948: Weak RNG
Published Sep 23, 2021
·Updated
Vulnerability in the generation of session IDs in revive-adserver < 5.3.0, based on the cryptographically insecure uniqid() PHP function. Under some circumstances, an attacker could theoretically be able to brute force session IDs in order to take over a specific account.
Affected Software
2 affected components
revive-adserver Revive Adserver<5.3.0
revive-adserver Revive Adserver=5.3.0-rc1
Remediation
Patch Available
Event History
Sep 23, 2021
CVE Published
via MITRE·12:44 PM
Data Sourced
via MITRE·12:44 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2021-22948?
CVE-2021-22948 is a vulnerability in the generation of session IDs in revive-adserver < 5.3.0.
2
What is the severity of CVE-2021-22948?
The severity of CVE-2021-22948 is high with a CVSS score of 7.1.
3
How can an attacker exploit CVE-2021-22948?
An attacker could theoretically brute force session IDs to take over a specific account.
4
What software versions are affected by CVE-2021-22948?
Revive-adserver versions prior to 5.3.0, including 5.3.0-rc1, are affected.
5
How can I fix CVE-2021-22948?
To fix CVE-2021-22948, upgrade to version 5.3.0 or later of revive-adserver.