RaqibCTI
CVE

CVE-2024-39891

P2
Twilio Authy Information Disclosure Vulnerability
Twilio · Authy
Date added (CISA)
2024-07-23
Remediation due
2024-08-13
Known ransomware use
Not indicated
Remediation priority
P2past CISA due date

Description

Twilio Authy contains an information disclosure vulnerability in its API that allows an unauthenticated endpoint to accept a request containing a phone number and respond with information about whether the phone number was registered with Authy.

Source: NVD ↗ · CISA KEV Catalog ↗