Multiple classes used within Apereo... CVE-2019-10754

5.5 AV AC AU C I A
发布: 2019-09-23
修订: 2019-09-24

Multiple classes used within Apereo CAS before release 6.1.0-RC5 makes use of apache commons-lang3 RandomStringUtils for token and ID generation which makes them predictable due to RandomStringUtils PRNG's algorithm not being cryptographically strong.

0%
暂无可用Exp或PoC
当前有5条受影响产品信息