Vulnerabilities > CVE-2019-10755 - Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) vulnerability in Pac4J
Attack vector
NETWORK Attack complexity
LOW Privileges required
HIGH Confidentiality impact
HIGH Integrity impact
NONE Availability impact
NONE Summary
The SAML identifier generated within SAML2Utils.java was found to make use of the apache commons-lang3 RandomStringUtils class which makes them predictable due to RandomStringUtils PRNG's algorithm not being cryptographically strong. This issue only affects the 3.X release of pac4j-saml.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 16 |