In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsLearn about Incorrect Usage of Seeds in Pseudo-Random Number Generator (PRNG) vulnerabilities in an interactive lesson.
Start learningThere is no fixed version for org.apache.cocoon:cocoon-sitemap-impl
.
Affected versions of this package are vulnerable to Incorrect Usage of Seeds in Pseudo-Random Number Generator (PRNG) in the ContinuationsManagerImpl
class, which uses the application's startup time as the seed. An attacker can guess continuation IDs and access unauthorized continuations by predicting this value.
Note: This package is no longer maintained so a fix is not expected.
This vulnerability can be avoided by enabling the session-bound-continuations
option.