Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v2r2-7qm7-jj6v

Опубликовано: 16 апр. 2019
Источник: github
Github: Прошло ревью
CVSS3: 5.3

Описание

Spring Security uses insufficiently random values

Spring Security versions 4.2.x prior to 4.2.12, 5.0.x prior to 5.0.12, and 5.1.x prior to 5.1.5 contain an insecure randomness vulnerability when using SecureRandomFactoryBean#setSeed to configure a SecureRandom instance. In order to be impacted, an honest application must provide a seed and make the resulting random material available to an attacker for inspection.

Пакеты

Наименование

org.springframework.security:spring-security-core

maven
Затронутые версииВерсия исправления

>= 4.2.0, < 4.2.12

4.2.12

Наименование

org.springframework.security:spring-security-core

maven
Затронутые версииВерсия исправления

>= 5.0.0, < 5.0.12

5.0.12

Наименование

org.springframework.security:spring-security-core

maven
Затронутые версииВерсия исправления

>= 5.1.0, < 5.1.5

5.1.5

EPSS

Процентиль: 83%
0.01924
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-330

Связанные уязвимости

CVSS3: 5.3
ubuntu
почти 7 лет назад

Spring Security versions 4.2.x prior to 4.2.12, 5.0.x prior to 5.0.12, and 5.1.x prior to 5.1.5 contain an insecure randomness vulnerability when using SecureRandomFactoryBean#setSeed to configure a SecureRandom instance. In order to be impacted, an honest application must provide a seed and make the resulting random material available to an attacker for inspection.

CVSS3: 3.3
redhat
почти 7 лет назад

Spring Security versions 4.2.x prior to 4.2.12, 5.0.x prior to 5.0.12, and 5.1.x prior to 5.1.5 contain an insecure randomness vulnerability when using SecureRandomFactoryBean#setSeed to configure a SecureRandom instance. In order to be impacted, an honest application must provide a seed and make the resulting random material available to an attacker for inspection.

CVSS3: 5.3
nvd
почти 7 лет назад

Spring Security versions 4.2.x prior to 4.2.12, 5.0.x prior to 5.0.12, and 5.1.x prior to 5.1.5 contain an insecure randomness vulnerability when using SecureRandomFactoryBean#setSeed to configure a SecureRandom instance. In order to be impacted, an honest application must provide a seed and make the resulting random material available to an attacker for inspection.

CVSS3: 5.3
debian
почти 7 лет назад

Spring Security versions 4.2.x prior to 4.2.12, 5.0.x prior to 5.0.12, ...

EPSS

Процентиль: 83%
0.01924
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-330