CVE Published: 23/09/2019 |
CVE Updated: 04/08/2024 |
CVE Year: 2019 Source: snyk |
Vendor: n/a |
Product: PAC4J For SAML Protocol Status : PUBLISHED
CVE-2019-10755 Description
The SAML identifier generated within SAML2Utils.java was found to make use of the apache commons-lang3 RandomStringUtils class which makes them predictable due to RandomStringUtils PRNG\'s algorithm not being cryptographically strong. This issue only affects the 3.X release of pac4j-saml.