GHSA-q3jg-4c82-j4xh
Dashboard / Vulnerabilities / GHSA-q3jg-4c82-j4xh
Summary: Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) in Pivotal CredHub Service Broker
Details: Pivotal CredHub Service Broker, versions prior to 1.1.0, uses a guessable form of random number generation in creating service broker's UAA client. A remote malicious user may guess the client secret and obtain or modify credentials for users of the CredHub Service.
References: https://nvd.nist.gov/vuln/detail/CVE-2018-15795, https://github.com/advisories/GHSA-q3jg-4c82-j4xh, https://pivotal.io/security/cve-2018-15795, http://www.securityfocus.com/bid/105915
Affected packages
Package
Name: org.springframework.credhub:spring-credhub-core
Purl: pkg:maven/org.springframework.credhub/spring-credhub-core
Affected ranges
Type: ECOSYSTEM
Events:
