# CVE-2024-6890

## Summary

- **CVE ID:** CVE-2024-6890
- **Severity:** UNKNOWN
- **CVSS Score:** 0
- **CWE:** CWE-321, CWE-334, CWE-799
- **Published:** Aug 7, 2024
- **Last Modified:** Mar 13, 2026

## Description

Password reset tokens are generated using an insecure source of randomness. Attackers who know the username of the Journyx installation user can bruteforce the password reset and change the administrator password.

## Affected Products

- Journyx — Journyx (jtime) (11.5.4)

## References

- [CNA](https://korelogic.com/Resources/Advisories/KL-001-2024-007.txt)
- [CVE](http://seclists.org/fulldisclosure/2024/Aug/5)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.72%
- **EPSS Percentile:** 51.7

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._