QID 981185
QID 981185: Java (maven) Security Update for com.github.penggle:kaptcha (GHSA-8q89-pwhh-7wfq)
text/impl/DefaultTextCreator.java, text/impl/ChineseTextProducer.java, and text/impl/FiveLetterFirstNameTextCreator.java in kaptcha 2.3.2 use the Random (rather than SecureRandom) function for generating CAPTCHA values, which makes it easier for remote attackers to bypass intended access restrictions via a brute-force approach.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-8q89-pwhh-7wfq for updates pertaining to this vulnerability.
Vendor References
- GHSA-8q89-pwhh-7wfq -
github.com/advisories/GHSA-8q89-pwhh-7wfq
CVEs related to QID 981185
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-8q89-pwhh-7wfq | com.github.penggle:kaptcha |
|