Vulnerability Description
The SAML identifier generated within SAML2Utils.java was found to make use of the apache commons-lang3 RandomStringUtils class which makes them predictable due to RandomStringUtils PRNG's algorithm not being cryptographically strong. This issue only affects the 3.X release of pac4j-saml.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Pac4J | Pac4J | >= 3.0.0, <= 3.8.2 |
Related Weaknesses (CWE)
References
- https://snyk.io/vuln/SNYK-JAVA-ORGPAC4J-467407PatchThird Party Advisory
- https://snyk.io/vuln/SNYK-JAVA-ORGPAC4J-467407PatchThird Party Advisory
FAQ
What is CVE-2019-10755?
CVE-2019-10755 is a vulnerability with a CVSS score of 4.9 (MEDIUM). The SAML identifier generated within SAML2Utils.java was found to make use of the apache commons-lang3 RandomStringUtils class which makes them predictable due to RandomStringUtils PRNG's algorithm no...
How severe is CVE-2019-10755?
CVE-2019-10755 has been rated MEDIUM with a CVSS base score of 4.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-10755?
Check the references section above for vendor advisories and patch information. Affected products include: Pac4J Pac4J.