Security Advisory

CVE-2006-6969

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2007-02-07 11:00:00
Last updated 2024-08-07 20:50:04
Assigner mitre
State PUBLISHED

Description

Jetty before 4.2.27, 5.1 before 5.1.12, 6.0 before 6.0.2, and 6.1 before 6.1.0pre3 generates predictable session identifiers using java.util.random, which makes it easier for remote attackers to guess a session identifier through brute force attacks, bypass authentication requirements, and possibly conduct cross-site request forgery attacks.