CVE-2019-10754: Weak RNG
Multiple classes used within Apereo CAS before release 6.1.0-RC5 makes use of apache commons-lang3 RandomStringUtils for token and ID generation which makes them predictable due to RandomStringUtils PRNG's algorithm not being cryptographically strong.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is CVE-2019-10754?
CVE-2019-10754 is a vulnerability found in Apereo CAS before release 6.1.0-RC5 that makes token and ID generation predictable due to the weak algorithm used.
What software is affected by CVE-2019-10754?
Apereo Central Authentication Service versions 6.0.5.1, 6.1.0-rc1, 6.1.0-rc2, 6.1.0-rc3, and 6.1.0-rc4 are affected by CVE-2019-10754.
What is the severity of CVE-2019-10754?
CVE-2019-10754 has a severity rating of 8.1, which is considered high.
How can I fix CVE-2019-10754?
To fix CVE-2019-10754, update Apereo CAS to release 6.1.0-RC5 or later.
Where can I find more information about CVE-2019-10754?
More information about CVE-2019-10754 can be found at the following references: [Link 1](https://snyk.io/vuln/SNYK-JAVA-ORGAPEREOCAS-467402), [Link 2](https://snyk.io/vuln/SNYK-JAVA-ORGAPEREOCAS-467404), [Link 3](https://snyk.io/vuln/SNYK-JAVA-ORGAPEREOCAS-467406).