← Browse

CVE-2024-39891

Act now ● On CISA KEV — actively exploited

Actively exploited — on the CISA KEV list.

CVSS base
EPSS — probability of exploitation (30 days)
1.7%
75.7th percentile
CISA KEV
Listed
Added 2024-07-23 · patch by 2024-08-13
Weakness / dates
Published — · modified —

Timeline

Description

Twilio Authy contains an information disclosure vulnerability in its API that allows an unauthenticated endpoint to accept a request containing a phone number and respond with information about whether the phone number was registered with Authy.

Official: NVD · CVE.org