First published: Thu Sep 23 2021(Updated: )
Vulnerability in the generation of session IDs in revive-adserver < 5.3.0, based on the cryptographically insecure uniqid() PHP function. Under some circumstances, an attacker could theoretically be able to brute force session IDs in order to take over a specific account.
Credit: support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
Revive-adserver Revive Adserver | <5.3.0 | |
Revive-adserver Revive Adserver | =5.3.0-rc1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-22948 is a vulnerability in the generation of session IDs in revive-adserver < 5.3.0.
The severity of CVE-2021-22948 is high with a CVSS score of 7.1.
An attacker could theoretically brute force session IDs to take over a specific account.
Revive-adserver versions prior to 5.3.0, including 5.3.0-rc1, are affected.
To fix CVE-2021-22948, upgrade to version 5.3.0 or later of revive-adserver.