Description
text/impl/DefaultTextCreator.java, text/impl/ChineseTextProducer.java, and text/impl/FiveLetterFirstNameTextCreator.java in kaptcha 2.3.2 use the Random (rather than SecureRandom) function for generating CAPTCHA values, which makes it easier for remote attackers to bypass intended access restrictions via a brute-force approach.
Remediation
References
https://github.com/penggle/kaptcha/issues/3
Related Vulnerabilities
CVE-2010-2245 Vulnerability in maven package org.apache.wink:wink-server
CVE-2020-10727 Vulnerability in maven package org.apache.activemq:artemis-server
CVE-2019-3868 Vulnerability in maven package org.keycloak:keycloak-core
CVE-2015-8860 Vulnerability in maven package org.webjars.npm:tar
CVE-2011-4343 Vulnerability in maven package org.apache.myfaces.core.internal:myfaces-impl-shared