Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v2r2-7qm7-jj6v

Опубликовано: 16 апр. 2019
Источник: github
Github: Прошло ревью
CVSS3: 5.3

Описание

Spring Security uses insufficiently random values

Spring Security versions 4.2.x prior to 4.2.12, 5.0.x prior to 5.0.12, and 5.1.x prior to 5.1.5 contain an insecure randomness vulnerability when using SecureRandomFactoryBean#setSeed to configure a SecureRandom instance. In order to be impacted, an honest application must provide a seed and make the resulting random material available to an attacker for inspection.

Пакеты

Наименование

org.springframework.security:spring-security-core

maven
Затронутые версииВерсия исправления

>= 4.2.0, < 4.2.12

4.2.12

Наименование

org.springframework.security:spring-security-core

maven
Затронутые версииВерсия исправления

>= 5.0.0, < 5.0.12

5.0.12

Наименование

org.springframework.security:spring-security-core

maven
Затронутые версииВерсия исправления

>= 5.1.0, < 5.1.5

5.1.5

EPSS

Процентиль: 78%
0.01884
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-330

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 7 лет назад

Spring Security versions 4.2.x prior to 4.2.12, 5.0.x prior to 5.0.12, and 5.1.x prior to 5.1.5 contain an insecure randomness vulnerability when using SecureRandomFactoryBean#setSeed to configure a SecureRandom instance. In order to be impacted, an honest application must provide a seed and make the resulting random material available to an attacker for inspection.

CVSS3: 3.3
redhat
больше 7 лет назад

Spring Security versions 4.2.x prior to 4.2.12, 5.0.x prior to 5.0.12, and 5.1.x prior to 5.1.5 contain an insecure randomness vulnerability when using SecureRandomFactoryBean#setSeed to configure a SecureRandom instance. In order to be impacted, an honest application must provide a seed and make the resulting random material available to an attacker for inspection.

CVSS3: 5.3
nvd
больше 7 лет назад

Spring Security versions 4.2.x prior to 4.2.12, 5.0.x prior to 5.0.12, and 5.1.x prior to 5.1.5 contain an insecure randomness vulnerability when using SecureRandomFactoryBean#setSeed to configure a SecureRandom instance. In order to be impacted, an honest application must provide a seed and make the resulting random material available to an attacker for inspection.

CVSS3: 5.3
debian
больше 7 лет назад

Spring Security versions 4.2.x prior to 4.2.12, 5.0.x prior to 5.0.12, ...

EPSS

Процентиль: 78%
0.01884
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-330