Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cf3q-vg8w-mw84

Опубликовано: 24 июн. 2024
Источник: github
Github: Прошло ревью
CVSS4: 9.1
CVSS3: 9.1

Описание

Apache StreamPipes: Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) in Recovery Token Generation

Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) vulnerability in Apache StreamPipes user self-registration and password recovery mechanism. This allows an attacker to guess the recovery token in a reasonable time and thereby to take over the attacked user's account. This issue affects Apache StreamPipes: from 0.69.0 through 0.93.0.

Users are recommended to upgrade to version 0.95.0, which fixes the issue.

Пакеты

Наименование

org.apache.streampipes:streampipes-resource-management

maven
Затронутые версииВерсия исправления

>= 0.69.0, < 0.95.0

0.95.0

EPSS

Процентиль: 99%
0.74201
Высокий

9.1 Critical

CVSS4

9.1 Critical

CVSS3

Дефекты

CWE-338

Связанные уязвимости

CVSS3: 9.1
nvd
больше 1 года назад

Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) vulnerability in Apache StreamPipes user self-registration and password recovery mechanism. This allows an attacker to guess the recovery token in a reasonable time and thereby to take over the attacked user's account. This issue affects Apache StreamPipes: from 0.69.0 through 0.93.0. Users are recommended to upgrade to version 0.95.0, which fixes the issue.

EPSS

Процентиль: 99%
0.74201
Высокий

9.1 Critical

CVSS4

9.1 Critical

CVSS3

Дефекты

CWE-338