Description
Spring Security versions 4.2.x prior to 4.2.12, 5.0.x prior to 5.0.12, and 5.1.x prior to 5.1.5 contain an insecure randomness vulnerability when using SecureRandomFactoryBean#setSeed to configure a SecureRandom instance. In order to be impacted, an honest application must provide a seed and make the resulting random material available to an attacker for inspection.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-1794-1 | libspring-security-2.0-java security update |
EUVD |
EUVD-2019-0437 | Spring Security versions 4.2.x prior to 4.2.12, 5.0.x prior to 5.0.12, and 5.1.x prior to 5.1.5 contain an insecure randomness vulnerability when using SecureRandomFactoryBean#setSeed to configure a SecureRandom instance. In order to be impacted, an honest application must provide a seed and make the resulting random material available to an attacker for inspection. |
Github GHSA |
GHSA-v2r2-7qm7-jj6v | Spring Security uses insufficiently random values |
References
History
No history.
Status: PUBLISHED
Assigner: dell
Published:
Updated: 2024-09-17T00:02:03.823Z
Reserved: 2019-01-03T00:00:00.000Z
Link: CVE-2019-3795
No data.
Status : Modified
Published: 2019-04-09T16:29:01.837
Modified: 2024-11-21T04:42:33.430
Link: CVE-2019-3795
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
EUVD
Github GHSA