CVE-2025-24783: Apache Cocoon: continuations may not be private

Arnout Engelen <[email protected]> Mon, 27 Jan 2025 14:28:12 +0000
Newsgroups gmane.text.xml.cocoon.user
Message-ID <[email protected]>
Severity: low

Affected versions:

- Apache Cocoon: all versions

Description:

** UNSUPPORTED WHEN ASSIGNED ** Incorrect Usage of Seeds in Pseudo-Random =
Number Generator (PRNG) vulnerability in Apache Cocoon.

This issue affects Apache Cocoon: all versions.

When a continuation is created, it gets a random identifier. Because the =
random number generator used to generate these identifiers was seeded with =
the startup time, it may not have been sufficiently unpredictable, and an =
attacker could use this to guess continuation ids and look up continuations=
 they should not have had access to.

As a mitigation, you may enable the "session-bound-continuations" option to=
 make sure continuations are not shared across sessions.


As this project is retired, we do not plan to release a version that fixes =
this issue. Users are recommended to find an alternative or restrict access=
 to the instance to trusted users.

NOTE: This vulnerability only affects products that are no longer supported=
 by the maintainer.

Credit:

Xiangfan Wu from the StarMap Team of Legendsec at Qi-Anxin Group (finder)

References:

https://attic.apache.org/projects/cocoon.html
https://www.cve.org/CVERecord?id=3DCVE-2025-24783