CVE-2018-18531
19.10.2018, 20:29
text/impl/DefaultTextCreator.java, text/impl/ChineseTextProducer.java, and text/impl/FiveLetterFirstNameTextCreator.java in kaptcha 2.3.2 use the Random (rather than SecureRandom) function for generating CAPTCHA values, which makes it easier for remote attackers to bypass intended access restrictions via a brute-force approach.Enginsight
Vendor | Product | Version |
---|---|---|
kaptcha_project | kaptcha | 2.3.2 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration