CVE-2019-5440
Last modified
CVE-2019-5440 is a vulnerability of currently unknown severity. Use of cryptographically weak PRNG in the password recovery token generation of Revive Adserver < v4.2.1 causes a potential authentication bypass attack if an attacker exploits the password recovery functionality. In lib/OA/Dal/PasswordRecovery.php, the function generateRecoveryId() generates a password reset token that relies on the PHP uniqid function and consequently depends only on the current server time, which is often visible in an HTTP Date header.. EPSS estimates a 1.58% chance of exploitation in the next 30 days.
Description
Use of cryptographically weak PRNG in the password recovery token generation of Revive Adserver < v4.2.1 causes a potential authentication bypass attack if an attacker exploits the password recovery functionality. In lib/OA/Dal/PasswordRecovery.php, the function generateRecoveryId() generates a password reset token that relies on the PHP uniqid function and consequently depends only on the current server time, which is often visible in an HTTP Date header.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Revive-Adserver | Revive Adserver | < 4.2.1 |
References
- https://hackerone.com/reports/576504Exploit, Third Party Advisory
- https://hackerone.com/reports/576504Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-5440?
How severe is CVE-2019-5440?
How do I fix CVE-2019-5440?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-5434An attacker could send a specifically crafted payload to the…
- CVE-2019-5435An integer overflow in curl's URL API results in a buffer ov…
- CVE-2019-5436A heap buffer overflow in the TFTP receiving code allows for…7.8
- CVE-2019-5437Information exposure through the directory listing in npm's …
- CVE-2019-5438Path traversal using symlink in npm harp module versions <= …5.3
- CVE-2019-5439A Buffer Overflow in VLC Media Player < 3.0.7 causes a crash…
- CVE-2019-5441Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2019-5442XML Entity Expansion (Billion Laughs Attack) on Pippo 1.12.0…7.5
- CVE-2019-5443A non-privileged user or program can put code and a config f…7.8
- CVE-2019-5444Path traversal vulnerability in version up to v1.1.3 in serv…5.3
- CVE-2019-5445DoS in EdgeMAX EdgeSwitch prior to 1.8.2 allow an Admin user…4.9
- CVE-2019-5446Command Injection in EdgeMAX EdgeSwitch prior to 1.8.2 allow…7.2
Are you affected by CVE-2019-5440?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
