CVE-2019-3795
Severity CVSS v4.0:
Pending analysis
Type:
CWE-330
Use of Insufficiently Random Value
Publication date:
09/04/2019
Last modified:
02/11/2021
Description
Spring Security versions 4.2.x prior to 4.2.12, 5.0.x prior to 5.0.12, and 5.1.x prior to 5.1.5 contain an insecure randomness vulnerability when using SecureRandomFactoryBean#setSeed to configure a SecureRandom instance. In order to be impacted, an honest application must provide a seed and make the resulting random material available to an attacker for inspection.
Impact
Base Score 3.x
5.30
Severity 3.x
MEDIUM
Base Score 2.0
5.00
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:vmware:spring_security:*:*:*:*:*:*:*:* | 4.2.0 (including) | 4.2.12 (excluding) |
| cpe:2.3:a:vmware:spring_security:*:*:*:*:*:*:*:* | 5.0.0 (including) | 5.0.12 (excluding) |
| cpe:2.3:a:vmware:spring_security:*:*:*:*:*:*:*:* | 5.1.0 (including) | 5.1.5 (excluding) |
| cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



