CVE-2019-10755
23.09.2019, 23:15
The SAML identifier generated within SAML2Utils.java was found to make use of the apache commons-lang3 RandomStringUtils class which makes them predictable due to RandomStringUtils PRNG's algorithm not being cryptographically strong. This issue only affects the 3.X release of pac4j-saml.
Vendor | Product | Version |
---|---|---|
pac4j | pac4j | 3.0.0 ≤ 𝑥 ≤ 3.8.2 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration