CVE-2019-3795
Dashboard / Vulnerabilities / CVE-2019-3795
Summary:
Details: Spring Security versions 4.2.x prior to 4.2.12, 5.0.x prior to 5.0.12, and 5.1.x prior to 5.1.5 contain an insecure randomness vulnerability when using SecureRandomFactoryBean#setSeed to configure a SecureRandom instance. In order to be impacted, an honest application must provide a seed and make the resulting random material available to an attacker for inspection.
References: http://www.securityfocus.com/bid/107802, https://lists.debian.org/debian-lts-announce/2019/05/msg00026.html, https://pivotal.io/security/cve-2019-3795
Affected packages
Package
Name:
Purl:
Affected ranges
Type: GIT
Events:
Introduced- 24fcb6c45a55333e5b856b6c73f14b68ceca0e19
Affected versions
5.1.4.RELEASE
5.1.3.RELEASE
5.1.2.RELEASE
5.1.1.RELEASE
5.1.0.RELEASE
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
