CVE-2024-39891
Act now ● On CISA KEV — actively exploited
Actively exploited — on the CISA KEV list.
CVSS base
—
EPSS — probability of exploitation (30 days)
1.7%
75.7th percentile
CISA KEV
Listed
Added 2024-07-23 · patch by 2024-08-13
Weakness / dates
—
Published — · modified —
Description
Twilio Authy contains an information disclosure vulnerability in its API that allows an unauthenticated endpoint to accept a request containing a phone number and respond with information about whether the phone number was registered with Authy.