CVE-2024-39891

In the Twilio Authy API, accessed by Authy Android before 25.1.0 and Authy iOS before 26.1.0, an unauthenticated endpoint provided access to certain phone-number data, as exploited in the wild in June 2024. Specifically, the endpoint accepted a stream of requests containing phone numbers, and responded with information about whether each phone number was registered with Authy. (Authy accounts were not compromised, however.)
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:twilio:authy:*:*:*:*:*:iphone_os:*:*
cpe:2.3:a:twilio:authy_authenticator:*:*:*:*:*:android:*:*

History

20 Dec 2024, 16:15

Type Values Removed Values Added
References () https://www.twilio.com/en-us/changelog - Product, Release Notes () https://www.twilio.com/en-us/changelog - Release Notes

24 Jul 2024, 14:38

Type Values Removed Values Added
First Time Twilio authy Authenticator
Twilio authy
Twilio
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.3
References () https://cwe.mitre.org/data/definitions/203.html - () https://cwe.mitre.org/data/definitions/203.html - Technical Description
References () https://www.bleepingcomputer.com/news/security/hackers-abused-api-to-verify-millions-of-authy-mfa-phone-numbers/ - () https://www.bleepingcomputer.com/news/security/hackers-abused-api-to-verify-millions-of-authy-mfa-phone-numbers/ - Press/Media Coverage
References () https://www.twilio.com/docs/usage/security/reporting-vulnerabilities - () https://www.twilio.com/docs/usage/security/reporting-vulnerabilities - Product
References () https://www.twilio.com/en-us/changelog - () https://www.twilio.com/en-us/changelog - Product, Release Notes
CPE cpe:2.3:a:twilio:authy:*:*:*:*:*:iphone_os:*:*
cpe:2.3:a:twilio:authy_authenticator:*:*:*:*:*:android:*:*
CWE CWE-203

03 Jul 2024, 22:15

Type Values Removed Values Added
Summary In the Twilio Authy API, accessed by Authy Android before 25.1.0 and Authy iOS before 26.1.0, an unauthenticated endpoint provided access to certain phone-number data. (Authy accounts were not compromised, however.) In the Twilio Authy API, accessed by Authy Android before 25.1.0 and Authy iOS before 26.1.0, an unauthenticated endpoint provided access to certain phone-number data, as exploited in the wild in June 2024. Specifically, the endpoint accepted a stream of requests containing phone numbers, and responded with information about whether each phone number was registered with Authy. (Authy accounts were not compromised, however.)
References
  • () https://www.bleepingcomputer.com/news/security/hackers-abused-api-to-verify-millions-of-authy-mfa-phone-numbers/ -

02 Jul 2024, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-02 18:15

Updated : 2024-12-20 16:15


NVD link : CVE-2024-39891

Mitre link : CVE-2024-39891


JSON object : View

Products Affected

twilio

  • authy
  • authy_authenticator
CWE
CWE-203

Observable Discrepancy