[REVIVE-SA-2020-001] Revive Adserver Vulnerability

Matteo Beccati via Fulldisclosure <[email protected]> Tue, 21 Jan 2020 14:24:14 +0100
Newsgroups gmane.comp.security.fulldisclosure,gmane.comp.security.bugtraq
Message-ID <[email protected]>
========================================================================
Revive Adserver Security Advisory                     REVIVE-SA-2020-001
------------------------------------------------------------------------
https://www.revive-adserver.com/security/revive-sa-2020-001
------------------------------------------------------------------------
CVE-IDs:               t.b.a.
Date:                  2020-01-21
Risk Level:            Low
Applications affected: Revive Adserver
Versions affected:     <= 5.0.3
Versions not affected: >= 5.0.4
Website:               https://www.revive-adserver.com/
========================================================================


========================================================================
Vulnerability - Reflected XSS
========================================================================
Vulnerability Type:    Improper Neutralization of Input During Web Page
                       Generation ('Cross-site Scripting') [CWE-79]
CVE-ID:                t.b.a.
CVSS Base Score:       4.3
CVSSv3.1 Vector:       AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
CVSS Impact Subscore:  1.4
CVSS Exploitability Subscore: 2.8
========================================================================

Description
-----------
A reflected XSS vulnerability has been discovered in the publicly
accessible afr.php delivery script of Revive Adserver by Jacopo Tediosi.
There are currently no known exploits: the session identifier cannot
be accessed as it is stored in an http-only cookie as of v3.2.2. On
older versions, however, under specific circumstances, it could be
possible to steal the session identifier and gain access to the admin
interface.

Details
-------
The query string sent to the www/delivery/afr.php script was printed
back without proper escaping in a JavaScript context, allowing an
attacker to execute arbitrary JS code on the browser of the victim.


References
----------
https://hackerone.com/reports/775693
https://github.com/revive-adserver/revive-adserver/commit/327aaf10
https://github.com/revive-adserver/revive-adserver/commit/9ec2fa26
https://cwe.mitre.org/data/definitions/79.html



========================================================================
Solution
========================================================================

We strongly advise people to upgrade to the most recent 5.0.4 version of
Revive Adserver.


========================================================================
Contact Information
========================================================================

The security contact for Revive Adserver can be reached at:
<security AT revive-adserver DOT com>.

Please review https://www.revive-adserver.com/security/ before doing so.


-- 
Matteo Beccati
On behalf of the Revive Adserver Team
https://www.revive-adserver.com/
signature.asc (application/pgp-signature, 833 B)
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEEPMldaL+0mzdlEBc0eUOexCISQC4FAl4m+6cACgkQeUOexCIS
QC7z5w/+OXq1D7cwD3CyLTq8j0urNOoz7SQc7PVqlLURDZXlRnbzGQGjhpApYIss
2IrFJsfeplfjSYViYJCpnGi24i1Nw0hWFNVEsbDsIW2t9ntg7kjNfJb9y1v6Pi6T
xEPvIIkW9EXDwTOGsmqtf3a03uc+h9dFKvsiDv3KL/bUX5AHIx8yB8pOBttNt1V5
W+JUkNzXUOOW8JcvPGbZZzNfbptpVl4ZdBO6QhgV9ZsTl+Zf9vfeRmgeqTLwlkOf
Snc3esqri2JE8EbepDqguWAlQIze5kmRpmB03P45r5QsmFBtOuUnIKTgqbr/AI9b
Lu7CUOb2/zPn3ZeqODPMF38qbnLrL7iugQr7DM/yrVwGhq9Vj0rz0VcqhdKjzGWv
KdD492M3csAl5/uNlwKj2zb/Xsd1gTBhDq1bpJNRNNApOtPNcUF4Zx6n7RH8Iryg
Xoif34dW2Fmo+Qi/QYRvi9dpzhAh4Ez7eMojC4b8sWPOUFdoLryvoCeeI6gCLUh+
G3hRSvRFR2hwuF+y5zEWmKeggLAKpXin33/U636EbE0PabTBfHoRqFfcF0G6Tyyt
4lJtT8bG0vzik+YyiRVUFDB75scTbcUxLR/K7g+JZY5jDvjSjC7WbRlV/jaLINee
ReWrAiEy5NX/5+BIi+XgrnxzxeYb1SIbNSRl9b3zNn4zY8kDM40=
=N9To
-----END PGP SIGNATURE-----