Back

MEDIUM

Insecure Randomness When Using a SecureRandom Instance Constructed by Spring Security

Published Apr 9, 2019

Description

Spring Security versions 4.2.x prior to 4.2.12, 5.0.x prior to 5.0.12, and 5.1.x prior to 5.1.5 contain an insecure randomness vulnerability when using SecureRandomFactoryBean#setSeed to configure a SecureRandom instance. In order to be impacted, an honest application must provide a seed and make the resulting random material available to an attacker for inspection.

Affected products

Remediation

Red Hat statement

Red Hat OpenStack Platform's OpenDaylight versions 9 and 10 contain the vulnerable code. However, these OpenDaylight versions were released as technical preview with limited support and will therefore not be updated. Other OpenDaylight versions do not contain the vulnerable library.

Metrics

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner dell
Published Apr 9, 2019
Updated Sep 17, 2024
Reserved Jan 3, 2019
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Apr 2, 2019
GHSA-V2R2-7QM7-JJ6V