Apache StreamPipes from version 0.69.0 through 0.93.0 uses a cryptographically weak Pseudo-Random Number Generator (PRNG) in the recovery token generation mechanism. Given a valid token it's possible to predict all past and future generated tokens.
id: CVE-2024-29868
info:
name: Apache StreamPipes <= 0.93.0 - Use of Cryptographically Weak PRNG
...