QID 980235

QID 980235: Java (maven) Security Update for org.springframework.security:spring-security-core (GHSA-v2r2-7qm7-jj6v)

Spring Security versions 4.2.x prior to 4.2.12, 5.0.x prior to 5.0.12, and 5.1.x prior to 5.1.5 contain an insecure randomness vulnerability when using SecureRandomFactoryBean#setSeed to configure a SecureRandom instance. In order to be impacted, an honest application must provide a seed and make the resulting random material available to an attacker for inspection.

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as Medium - 5.3 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Customers are advised to refer to GHSA-v2r2-7qm7-jj6v for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 980235

    Software Advisories
    Advisory ID Software Component Link
    GHSA-v2r2-7qm7-jj6v org.springframework.security:spring-security-core URL Logo github.com/advisories/GHSA-v2r2-7qm7-jj6v