Tumblr security bug could have exposed users’ private data

Users' email addresses, passwords, and IP addresses were left vulnerable.

Oct 18, 2018, 3:27 pm


Mikael Thalen 

Mikael Thalen

Tumblr security bug left users' data vulnerable.


A major Tumblr security bug potentially exposed its users’ private data, but the blogging service says it has patched the problem.

The vulnerability, discovered by a security researcher participating in the company’s bug bounty program, involved Tumblr’s “Recommended Blogs” feature utilized by the service’s desktop app.

A blog post from the company explaining the issues states: “If a blog appeared in the module, it was possible, using debugging software in a certain way, to view certain account information associated with the blog.”

“This included email address, protected (hashed and salted) password of the Tumblr account, self-reported location (a no longer available feature), previously used email addresses, last login IP address, and the name of the blog associated with the account,” the company revealed.

Tumblr emphasized that an internal investigation yielded “no evidence of this security bug being abused” and said the issue was fixed within 12 hours of being reported.

“We’re not able to determine which specific accounts could have been affected by this bug, but our analysis has shown that the bug was rarely present,” Tumblr said.

The blog adds that users are not required to take any action as a result of the incident.

“It’s our mission to provide a safe space for people to express themselves freely and form communities around things they love. We feel that this bug could have affected that experience,” Tumblr concluded. “We want to be transparent with you about it. In our view, it’s simply the right thing to do.”

Bug bounty programs are used by numerous technology companies in order to reward security researchers for discovering issues that could be exploited by malicious actors.

While the most recent bug does not appear to have resulted in the compromise of private data, a hacker was able to steal account details from 65 million Tumblr users in 2016.


Share this article
*First Published: Oct 18, 2018, 3:27 pm