CVE-2019-3795
Spring Security versions 4.2.x prior to 4.2.12, 5.0.x prior to 5.0.12, and 5.1.x prior to 5.1.5 contain an insecure randomness vulnerability when using SecureRandomFactoryBean#setSeed to configure a SecureRandom instance.
Does this matter?
Lower severity and a low EPSS score (1.88%). Track it; it rarely justifies an emergency change on its own.
Description
Spring Security versions 4.2.x prior to 4.2.12, 5.0.x prior to 5.0.12, and 5.1.x prior to 5.1.5 contain an insecure randomness vulnerability when using SecureRandomFactoryBean#setSeed to configure a SecureRandom instance. In order to be impacted, an honest application must provide a seed and make the resulting random material available to an attacker for inspection.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 1.88% probability · 78th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-330
- Affected
- vmware/spring security · debian/debian linux
- Source
- security_alert@emc.com
References
- http://www.securityfocus.com/bid/107802Third Party Advisory, VDB Entry
- https://lists.debian.org/debian-lts-announce/2019/05/msg00026.htmlMailing List, Third Party Advisory
- https://pivotal.io/security/cve-2019-3795Vendor Advisory
- http://www.securityfocus.com/bid/107802Third Party Advisory, VDB Entry
- https://lists.debian.org/debian-lts-announce/2019/05/msg00026.htmlMailing List, Third Party Advisory
- https://pivotal.io/security/cve-2019-3795Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.