Vulnerabilities > Airsonic Project

DATE CVE VULNERABILITY TITLE RISK
2019-04-07 CVE-2019-10908 Incorrect Usage of Seeds in Pseudo-Random Number Generator (PRNG) vulnerability in Airsonic Project Airsonic 10.2.1
In Airsonic 10.2.1, RecoverController.java generates passwords via org.apache.commons.lang.RandomStringUtils, which uses java.util.Random internally.
network
low complexity
airsonic-project CWE-335
critical
9.8
2019-04-07 CVE-2019-10907 Inadequate Encryption Strength vulnerability in Airsonic Project Airsonic 10.2.1
Airsonic 10.2.1 uses Spring's default remember-me mechanism based on MD5, with a fixed key of airsonic in GlobalSecurityConfig.java.
network
low complexity
airsonic-project CWE-326
critical
9.8
2019-04-04 CVE-2018-20222 XXE vulnerability in Airsonic Project Airsonic
XXE issue in Airsonic before 10.1.2 during parse.
network
low complexity
airsonic-project CWE-611
critical
9.8