Логотип exploitDog
bind:CVE-2006-6969
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2006-6969

Количество 4

Количество 4

redhat логотип

CVE-2006-6969

почти 19 лет назад

Jetty before 4.2.27, 5.1 before 5.1.12, 6.0 before 6.0.2, and 6.1 before 6.1.0pre3 generates predictable session identifiers using java.util.random, which makes it easier for remote attackers to guess a session identifier through brute force attacks, bypass authentication requirements, and possibly conduct cross-site request forgery attacks.

CVSS3: 4.8
EPSS: Низкий
nvd логотип

CVE-2006-6969

больше 18 лет назад

Jetty before 4.2.27, 5.1 before 5.1.12, 6.0 before 6.0.2, and 6.1 before 6.1.0pre3 generates predictable session identifiers using java.util.random, which makes it easier for remote attackers to guess a session identifier through brute force attacks, bypass authentication requirements, and possibly conduct cross-site request forgery attacks.

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2006-6969

больше 18 лет назад

Jetty before 4.2.27, 5.1 before 5.1.12, 6.0 before 6.0.2, and 6.1 befo ...

CVSS2: 6.8
EPSS: Низкий
github логотип

GHSA-jg2x-r643-w2ch

больше 3 лет назад

Jetty Uses Predictable Session Identifiers

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2006-6969

Jetty before 4.2.27, 5.1 before 5.1.12, 6.0 before 6.0.2, and 6.1 before 6.1.0pre3 generates predictable session identifiers using java.util.random, which makes it easier for remote attackers to guess a session identifier through brute force attacks, bypass authentication requirements, and possibly conduct cross-site request forgery attacks.

CVSS3: 4.8
1%
Низкий
почти 19 лет назад
nvd логотип
CVE-2006-6969

Jetty before 4.2.27, 5.1 before 5.1.12, 6.0 before 6.0.2, and 6.1 before 6.1.0pre3 generates predictable session identifiers using java.util.random, which makes it easier for remote attackers to guess a session identifier through brute force attacks, bypass authentication requirements, and possibly conduct cross-site request forgery attacks.

CVSS2: 6.8
1%
Низкий
больше 18 лет назад
debian логотип
CVE-2006-6969

Jetty before 4.2.27, 5.1 before 5.1.12, 6.0 before 6.0.2, and 6.1 befo ...

CVSS2: 6.8
1%
Низкий
больше 18 лет назад
github логотип
GHSA-jg2x-r643-w2ch

Jetty Uses Predictable Session Identifiers

1%
Низкий
больше 3 лет назад

Уязвимостей на страницу