Tumblr Fixes Flaw that Made Accounts Vulnerable

Tumblr Fixes Flaw that Made Accounts Vulnerable

The information made vulnerable by the flaw would have let hackers obtain information they could use for phishing scams, harassment and other campaigns.

The blogging site Tumblr has disclosed a security flaw that could have exposed sensitive account information. The flaw has been fixed, and Tumblr said there was no evidence that the vulnerability had been exploited by bad users.

A security researcher discovered a security vulnerability in the part of the site that shows recommends blogs to logged-in users. If a blog showed up in the “recommended blogs” module, a debugging tool could be used to obtain their current and past email addresses, their scrambled password, their self-reported location and the IP address from their most recent sign-in.

The security researcher reported the bug to Tumblr, who fixed it within a day and awarded the reporter an unknown amount from the site’s bug bounty program.

The information made vulnerable by the flaw would have let hackers obtain information they could use for phishing scams, harassment and other campaigns.

In a blog post, Tumblr said that there is “no evidence” that anyone exploited the security vulnerability, and “nothing to suggest” that anyone accessed unprotected account information. The site wanted to “be transparent” about the incident regardless.  

About the Author

Jessica Davis is the Associate Content Editor for 1105 Media.

Featured

New Products

  • ResponderLink

    ResponderLink

    Shooter Detection Systems (SDS), an Alarm.com company and a global leader in gunshot detection solutions, has introduced ResponderLink, a groundbreaking new 911 notification service for gunshot events. ResponderLink completes the circle from detection to 911 notification to first responder awareness, giving law enforcement enhanced situational intelligence they urgently need to save lives. Integrating SDS’s proven gunshot detection system with Noonlight’s SendPolice platform, ResponderLink is the first solution to automatically deliver real-time gunshot detection data to 911 call centers and first responders. When shots are detected, the 911 dispatching center, also known as the Public Safety Answering Point or PSAP, is contacted based on the gunfire location, enabling faster initiation of life-saving emergency protocols.

  • Camden CM-221 Series Switches

    Camden CM-221 Series Switches

    Camden Door Controls is pleased to announce that, in response to soaring customer demand, it has expanded its range of ValueWave™ no-touch switches to include a narrow (slimline) version with manual override. This override button is designed to provide additional assurance that the request to exit switch will open a door, even if the no-touch sensor fails to operate. This new slimline switch also features a heavy gauge stainless steel faceplate, a red/green illuminated light ring, and is IP65 rated, making it ideal for indoor or outdoor use as part of an automatic door or access control system. ValueWave™ no-touch switches are designed for easy installation and trouble-free service in high traffic applications. In addition to this narrow version, the CM-221 & CM-222 Series switches are available in a range of other models with single and double gang heavy-gauge stainless steel faceplates and include illuminated light rings.

  • QCS7230 System-on-Chip (SoC)

    QCS7230 System-on-Chip (SoC)

    The latest Qualcomm® Vision Intelligence Platform offers next-generation smart camera IoT solutions to improve safety and security across enterprises, cities and spaces. The Vision Intelligence Platform was expanded in March 2022 with the introduction of the QCS7230 System-on-Chip (SoC), which delivers superior artificial intelligence (AI) inferencing at the edge.