CVE Published: 23/09/2019 |
CVE Updated: 04/08/2024 |
CVE Year: 2019 Source: snyk |
Vendor: n/a |
Product: Apereo CAS Status : PUBLISHED
CVE-2019-10754 Description
Multiple classes used within Apereo CAS before release 6.1.0-RC5 makes use of apache commons-lang3 RandomStringUtils for token and ID generation which makes them predictable due to RandomStringUtils PRNG\'s algorithm not being cryptographically strong.