Description
text/impl/DefaultTextCreator.java, text/impl/ChineseTextProducer.java, and text/impl/FiveLetterFirstNameTextCreator.java in kaptcha 2.3.2 use the Random (rather than SecureRandom) function for generating CAPTCHA values, which makes it easier for remote attackers to bypass intended access restrictions via a brute-force approach.
Remediation
References
https://github.com/penggle/kaptcha/issues/3
Related Vulnerabilities
CVE-2016-10584 Vulnerability in npm package dalek-browser-chrome-canary
CVE-2022-45207 Vulnerability in maven package org.jeecgframework.boot:jeecg-module-system
CVE-2020-7726 Vulnerability in npm package safe-object2
CVE-2015-5169 Vulnerability in maven package org.apache.struts:struts2-core
CVE-2019-0224 Vulnerability in maven package org.apache.jspwiki:jspwiki-builder