CVE-2019-10755

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
23/09/2019
Last modified:
24/09/2019

Description

The SAML identifier generated within SAML2Utils.java was found to make use of the apache commons-lang3 RandomStringUtils class which makes them predictable due to RandomStringUtils PRNG's algorithm not being cryptographically strong. This issue only affects the 3.X release of pac4j-saml.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:pac4j:pac4j:*:*:*:*:*:*:*:* 3.0.0 (including) 3.8.2 (including)


References to Advisories, Solutions, and Tools