Concierge::Sessions versions from 0.8.1 before 0.8.5 for Perl generate insecure session ids. The generate_session_id fun
Plack::Middleware::Session::Simple versions before 0.05 for Perl generates session ids insecurely. The default session
Amon2 versions before 6.17 for Perl use an insecure random_string implementation for security functions. In versions 6.
HTTP::Session versions before 0.54 for Perl defaults to using insecurely generated session ids. HTTP::Session defaults
Apache::Session::Generate::MD5 versions through 1.94 for Perl create insecure session id. Apache::Session::Generate::MD
Solstice::Session versions through 1440 for Perl generates session ids insecurely. The _generateSessionID method return
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, attachment download tokens are g
Apache::Session::Generate::ModUniqueId versions from 1.54 through 1.94 for Perl session ids are insecure. Apache::Sessi
Mojolicious::Plugin::Web::Auth::OAuth2 versions through 0.17 for Perl have an insecure default state parameter. When no
OpnForm derives editable-submission secrets from sequential row identifiers using Hashids with an empty default salt, al
In ManageEngine ADSelfService Plus, RecoveryManager Plus, M365 Manager Plus, and ADAudit Plus, the SSO tickets generated
Apache::SessionX versions through 2.01 for Perl create insecure session id. Apache::SessionX generates session ids inse
Dancer2 versions through 2.1.0 for Perl generate insecure session ids when required CSPRNG modules are unavailable. Dan
Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, Jervis uses determin
A missing S3 ownership verification in the Bedrock AgentCore Starter Toolkit before version v0.1.13 may allow a remote a
Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Fina
HTTP::Session2 versions before 1.12 for Perl for Perl may generate weak session ids using the rand() function. The HTTP
WebDyne::Session versions before 3.003_704 for Perl generate the session id insecurely. The session handler generates t
Apache::Session::Generate::SHA256 versions before 1.3.19 for Perl create insecure session ids. Apache::Session::Generat
Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior have a predictable registration ID derive
IBM Concert 1.0.0 through 2.2.0 creates temporary files with predictable names, which allows local users to overwrite ar
Dancer::Session::Abstract versions through 1.3522 for Perl generates session ids insecurely. The session id is generate
CGI::Session::ID::md5 versions before 4.49 for Perl generate predictable session ids from low-entropy sources. The gene
Amon2::Plugin::Web::CSRFDefender versions from 7.00 through 7.03 for Perl generate an insecure session id. The generate
Ado::Sessions versions through 0.935 for Perl generates insecure session ids. The session id is generated from a SHA-1
Naxclow device identifiers use fixed manufacturing prefixes combined with sequential counters, producing a fully predict
Mojolicious::Sessions::Storable versions through 0.05 for Perl generate session ids insecurely. The default session id
An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. URLAUTH token forgery can occur via a missing mboxk
Generation of Predictable Numbers or Identifiers vulnerability in Erlang/OTP kernel (inet_res, inet_db modules) allows D
Predictable bucket naming in Vertex AI Experiments in Google Cloud Vertex AI from version 1.21.0 up to (but not includin
The application generates uploaded file names using a weak and predictable method based on the request timestamp. This a
ATutor generates predictable email confirmation tokens due to the use of insufficiently random values in the account con
Frequently Asked Questions
What is CWE-340?
CWE-340 (CWE-340) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-340?
There are 32 CVE records associated with CWE-340 in our database. Of these, 11 are critical severity, 4 are high severity, and 13 are medium severity.
How can I protect against CWE-340 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-340 using AI-powered security agents.
Detect CWE-340 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-340 vulnerabilities across your infrastructure.
Get Started