CVE-2024-10141
A vulnerability, which was classified as problematic, was found in jsbroks COCO Annotator 0.11.1. This affects an unknown part of the component Session Handler. The manipulation of the argument SECRET_KEY leads to predictable from observable state. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.3
- CVSS vector
- CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.81%
- CWE
- CWE-341
- Published
- 2024-10-19
- Last modified
- 2026-03-13
Affected products
- jsbroks COCO Annotator
Weakness type
Related vulnerabilities
- CVE-2026-19565 — Apache::AppSamurai::Util versions through 1.01 for Perl generate predictable session authentication keys from the clock and process id in CreateSessionAuthKey
- CVE-2026-15571 — Keycloak-services: keycloak-services: predictable account-linking hash enables account takeover via malicious oidc client
- CVE-2026-42365 — GeoVision LPC2011/LPC2211 Web Interface guessable session cookie vulnerability
- CVE-2025-40780 — Cache poisoning due to weak PRNG
- CVE-2025-42925 — Predictable Object Identifier vulnerability in SAP NetWeaver AS Java (IIOP Service)
- CVE-2023-49259 — Bruteforcing authentication cookie for a given user
- CVE-2021-4277 — fredsmith utils Filename screenshot_sync predictable state
- CVE-2020-5365 — Dell EMC Isilon versions 8.2.2 and earlier contain a remotesupport vulnerability. The...