Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-3795

Опубликовано: 09 апр. 2019
Источник: nvd
CVSS3: 3.8
CVSS3: 5.3
CVSS2: 5
EPSS Низкий

Описание

Spring Security versions 4.2.x prior to 4.2.12, 5.0.x prior to 5.0.12, and 5.1.x prior to 5.1.5 contain an insecure randomness vulnerability when using SecureRandomFactoryBean#setSeed to configure a SecureRandom instance. In order to be impacted, an honest application must provide a seed and make the resulting random material available to an attacker for inspection.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:vmware:spring_security:*:*:*:*:*:*:*:*
Версия от 4.2.0 (включая) до 4.2.12 (исключая)
cpe:2.3:a:vmware:spring_security:*:*:*:*:*:*:*:*
Версия от 5.0.0 (включая) до 5.0.12 (исключая)
cpe:2.3:a:vmware:spring_security:*:*:*:*:*:*:*:*
Версия от 5.1.0 (включая) до 5.1.5 (исключая)
Конфигурация 2
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*

EPSS

Процентиль: 83%
0.01924
Низкий

3.8 Low

CVSS3

5.3 Medium

CVSS3

5 Medium

CVSS2

Дефекты

CWE-330
CWE-330

Связанные уязвимости

CVSS3: 5.3
ubuntu
почти 7 лет назад

Spring Security versions 4.2.x prior to 4.2.12, 5.0.x prior to 5.0.12, and 5.1.x prior to 5.1.5 contain an insecure randomness vulnerability when using SecureRandomFactoryBean#setSeed to configure a SecureRandom instance. In order to be impacted, an honest application must provide a seed and make the resulting random material available to an attacker for inspection.

CVSS3: 3.3
redhat
почти 7 лет назад

Spring Security versions 4.2.x prior to 4.2.12, 5.0.x prior to 5.0.12, and 5.1.x prior to 5.1.5 contain an insecure randomness vulnerability when using SecureRandomFactoryBean#setSeed to configure a SecureRandom instance. In order to be impacted, an honest application must provide a seed and make the resulting random material available to an attacker for inspection.

CVSS3: 5.3
debian
почти 7 лет назад

Spring Security versions 4.2.x prior to 4.2.12, 5.0.x prior to 5.0.12, ...

CVSS3: 5.3
github
почти 7 лет назад

Spring Security uses insufficiently random values

EPSS

Процентиль: 83%
0.01924
Низкий

3.8 Low

CVSS3

5.3 Medium

CVSS3

5 Medium

CVSS2

Дефекты

CWE-330
CWE-330