[REVIVE-SA-2020-001] Revive Adserver Vulnerability
Matteo Beccati via Fulldisclosure <[email protected]> Tue, 21 Jan 2020 14:24:14 +0100
| Newsgroups | gmane.comp.security.fulldisclosure,gmane.comp.security.bugtraq |
|---|---|
| Message-ID | <[email protected]> |
========================================================================
Revive Adserver Security Advisory REVIVE-SA-2020-001
------------------------------------------------------------------------
https://www.revive-adserver.com/security/revive-sa-2020-001
------------------------------------------------------------------------
CVE-IDs: t.b.a.
Date: 2020-01-21
Risk Level: Low
Applications affected: Revive Adserver
Versions affected: <= 5.0.3
Versions not affected: >= 5.0.4
Website: https://www.revive-adserver.com/
========================================================================
========================================================================
Vulnerability - Reflected XSS
========================================================================
Vulnerability Type: Improper Neutralization of Input During Web Page
Generation ('Cross-site Scripting') [CWE-79]
CVE-ID: t.b.a.
CVSS Base Score: 4.3
CVSSv3.1 Vector: AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
CVSS Impact Subscore: 1.4
CVSS Exploitability Subscore: 2.8
========================================================================
Description
-----------
A reflected XSS vulnerability has been discovered in the publicly
accessible afr.php delivery script of Revive Adserver by Jacopo Tediosi.
There are currently no known exploits: the session identifier cannot
be accessed as it is stored in an http-only cookie as of v3.2.2. On
older versions, however, under specific circumstances, it could be
possible to steal the session identifier and gain access to the admin
interface.
Details
-------
The query string sent to the www/delivery/afr.php script was printed
back without proper escaping in a JavaScript context, allowing an
attacker to execute arbitrary JS code on the browser of the victim.
References
----------
https://hackerone.com/reports/775693
https://github.com/revive-adserver/revive-adserver/commit/327aaf10
https://github.com/revive-adserver/revive-adserver/commit/9ec2fa26
https://cwe.mitre.org/data/definitions/79.html
========================================================================
Solution
========================================================================
We strongly advise people to upgrade to the most recent 5.0.4 version of
Revive Adserver.
========================================================================
Contact Information
========================================================================
The security contact for Revive Adserver can be reached at:
<security AT revive-adserver DOT com>.
Please review https://www.revive-adserver.com/security/ before doing so.
--
Matteo Beccati
On behalf of the Revive Adserver Team
https://www.revive-adserver.com/
signature.asc
(application/pgp-signature, 833 B)
-----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEPMldaL+0mzdlEBc0eUOexCISQC4FAl4m+6cACgkQeUOexCIS QC7z5w/+OXq1D7cwD3CyLTq8j0urNOoz7SQc7PVqlLURDZXlRnbzGQGjhpApYIss 2IrFJsfeplfjSYViYJCpnGi24i1Nw0hWFNVEsbDsIW2t9ntg7kjNfJb9y1v6Pi6T xEPvIIkW9EXDwTOGsmqtf3a03uc+h9dFKvsiDv3KL/bUX5AHIx8yB8pOBttNt1V5 W+JUkNzXUOOW8JcvPGbZZzNfbptpVl4ZdBO6QhgV9ZsTl+Zf9vfeRmgeqTLwlkOf Snc3esqri2JE8EbepDqguWAlQIze5kmRpmB03P45r5QsmFBtOuUnIKTgqbr/AI9b Lu7CUOb2/zPn3ZeqODPMF38qbnLrL7iugQr7DM/yrVwGhq9Vj0rz0VcqhdKjzGWv KdD492M3csAl5/uNlwKj2zb/Xsd1gTBhDq1bpJNRNNApOtPNcUF4Zx6n7RH8Iryg Xoif34dW2Fmo+Qi/QYRvi9dpzhAh4Ez7eMojC4b8sWPOUFdoLryvoCeeI6gCLUh+ G3hRSvRFR2hwuF+y5zEWmKeggLAKpXin33/U636EbE0PabTBfHoRqFfcF0G6Tyyt 4lJtT8bG0vzik+YyiRVUFDB75scTbcUxLR/K7g+JZY5jDvjSjC7WbRlV/jaLINee ReWrAiEy5NX/5+BIi+XgrnxzxeYb1SIbNSRl9b3zNn4zY8kDM40= =N9To -----END PGP SIGNATURE-----