« Volver al listado

CVE-2025-55127

Estado: AnalizadaMedia (5.4)—

HackerOne community member Dao Hoang Anh (yoyomiski) has reported an improper neutralization of whitespace in the username when adding new users. A username with leading or trailing whitespace could be virtually indistinguishable from its legitimate counterpart when the username is displayed in the UI, potentially leading to confusion.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-55127",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-55127",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "poc"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-11-20T21:19:19.157290Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.4,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.5,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "support@hackerone.com",
      "affectedData": [
        {
          "vendor": "Revive",
          "product": "Revive Adserver",
          "versions": [
            {
              "status": "affected",
              "version": "6",
              "versionType": "semver",
              "lessThanOrEqual": "6.0.2"
            },
            {
              "status": "unaffected",
              "version": "6.0.3",
              "versionType": "semver",
              "lessThanOrEqual": "6.0.3"
            }
          ]
        }
      ]
    }
  ],
  "published": "2025-11-20T19:16:19.027",
  "references": [
    {
      "url": "https://hackerone.com/reports/3413764",
      "tags": [
        "Exploit",
        "Issue Tracking"
      ],
      "source": "support@hackerone.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "description": [
        {
          "lang": "en",
          "value": "CWE-156"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "HackerOne community member Dao Hoang Anh (yoyomiski) has reported an improper neutralization of whitespace in the username when adding new users. A username with leading or trailing whitespace could be virtually indistinguishable from its legitimate counterpart when the username is displayed in the UI, potentially leading to confusion."
    },
    {
      "lang": "es",
      "value": "El miembro de la comunidad de HackerOne Dao Hoang Anh (yoyomiski) ha informado una neutralización impropia de espacios en blanco en el nombre de usuario al añadir nuevos usuarios. Un nombre de usuario con espacios en blanco iniciales o finales podría ser virtualmente indistinguible de su contraparte legítima cuando el nombre de usuario se muestra en la UI, potencialmente llevando a confusión."
    }
  ],
  "lastModified": "2026-06-17T09:41:18.997",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:aquaplatform:revive_adserver:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0CF3AE99-F6AB-419A-BB38-D1CDE5B195D2",
              "versionEndExcluding": "6.0.3",
              "versionStartIncluding": "6.0.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "support@hackerone.com"
}