QID 980861
QID 980861: Java (maven) Security Update for com.orientechnologies:orientdb-studio (GHSA-v6wr-fch2-vm5w)
server/network/protocol/http/OHttpSessionManager.java in the Studio component in OrientDB Server Community Edition before 2.0.15 and 2.1.x before 2.1.1 improperly relies on the java.util.Random class for generation of random Session ID values, which makes it easier for remote attackers to predict a value by determining the internal state of the PRNG in this class.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-v6wr-fch2-vm5w for updates pertaining to this vulnerability.
Vendor References
- GHSA-v6wr-fch2-vm5w -
github.com/advisories/GHSA-v6wr-fch2-vm5w
CVEs related to QID 980861
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-v6wr-fch2-vm5w | com.orientechnologies:orientdb-studio |
|