CVE-2024-29868

CVSS V2 None CVSS V3 None
Description
Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) vulnerability in Apache StreamPipes user self-registration and password recovery mechanism. This allows an attacker to guess the recovery token in a reasonable time and thereby to take over the attacked user's account. This issue affects Apache StreamPipes: from 0.69.0 through 0.93.0. Users are recommended to upgrade to version 0.95.0, which fixes the issue.
Overview
  • CVE ID
  • CVE-2024-29868
  • Assigner
  • apache
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2024-06-24T09:59:39.941Z
  • Last Modified Date
  • 2024-06-24T13:27:04.364Z
References
Reference URL Reference Tags
https://lists.apache.org/thread/g7t7zctvq2fysrw1x17flnc12592nhx7 vendor-advisory
History
Created Old Value New Value Data Type Notes
2024-06-26 17:32:44 Added to TrackCVE