VDB
Sign up
MEDIUM4.9

GHSA-rc75-cf5c-mxvh

Use of Cryptographically Weak Pseudo-Random Number Generator in org.pac4j:pac4j-saml

Quick fix

GHSA-rc75-cf5c-mxvh — org.pac4j:pac4j-saml: upgrade to the fixed version with the command below.

# pom.xml: bump <version>3.8.2</version> for org.pac4j:pac4j-saml

Details

The SAML identifier generated within SAML2Utils.java was found to make use of the apache commons-lang3 RandomStringUtils class which makes them predictable due to RandomStringUtils PRNG's algorithm not being cryptographically strong. This issue only affects the 3.X release of pac4j-saml.

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/org.pac4j:pac4j-saml
Introduced in: 0Fixed in: 3.8.2
Fix# pom.xml: bump <version>3.8.2</version> for org.pac4j:pac4j-saml

References