CVE-2024-6890
Severity CVSS v4.0:
Pending analysis
Type:
CWE-798
Use of Hard-coded Credentials
Publication date:
07/08/2024
Last modified:
08/08/2024
Description
Password reset tokens are generated using an insecure source of randomness. Attackers who know the username of the Journyx installation user can bruteforce the password reset and change the administrator password.
Impact
Base Score 3.x
8.80
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:journyx:journyx:11.5.4:*:*:*:*:linux:*:* |
To consult the complete list of CPE names with products and versions, see this page



