CVE-2019-11641

Anomali Agave (formerly Drupot) through 1.0.0 fails to avoid fingerprinting by including predictable data and minimal variation in size within HTML templates, giving attackers the ability to detect and avoid this system.
References
Link Resource
https://github.com/threatstream/agave/issues/1 Issue Tracking Third Party Advisory
https://github.com/threatstream/agave/issues/1 Issue Tracking Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:anomali:agave:*:*:*:*:*:*:*:*

History

21 Nov 2024, 04:21

Type Values Removed Values Added
References () https://github.com/threatstream/agave/issues/1 - Issue Tracking, Third Party Advisory () https://github.com/threatstream/agave/issues/1 - Issue Tracking, Third Party Advisory

Information

Published : 2019-05-01 18:29

Updated : 2024-11-21 04:21


NVD link : CVE-2019-11641

Mitre link : CVE-2019-11641

CVE.ORG link : CVE-2019-11641


JSON object : View

Products Affected

anomali

  • agave
CWE
CWE-330

Use of Insufficiently Random Values