Description
Multiple classes used within Apereo CAS before release 6.1.0-RC5 makes use of apache commons-lang3 RandomStringUtils for token and ID generation which makes them predictable due to RandomStringUtils PRNG's algorithm not being cryptographically strong.
Remediation
References
https://snyk.io/vuln/SNYK-JAVA-ORGAPEREOCAS-467402
https://snyk.io/vuln/SNYK-JAVA-ORGAPEREOCAS-467404
https://snyk.io/vuln/SNYK-JAVA-ORGAPEREOCAS-467406
https://snyk.io/vuln/SNYK-JAVA-ORGAPEREOCAS-468868
https://snyk.io/vuln/SNYK-JAVA-ORGAPEREOCAS-468869
Related Vulnerabilities
CVE-2023-50571 Vulnerability in maven package org.jeasy:easy-rules-mvel
CVE-2019-18798 Vulnerability in npm package node-sass
CVE-2021-22096 Vulnerability in maven package org.springframework:spring-webflux
CVE-2021-39154 Vulnerability in maven package com.thoughtworks.xstream:xstream
CVE-2023-40815 Vulnerability in maven package org.opencrx:opencrx-core-models