{"id":"GHSA-4c72-mrhf-23cg","summary":"Apache Syncope uses a weak PNRG","details":"Apache Syncope 1.1.x before 1.1.8 uses weak random values to generate passwords, which makes it easier for remote attackers to guess the password via a brute force attack.","aliases":["CVE-2014-3503"],"modified":"2024-12-08T05:27:43.019566Z","published":"2022-05-14T02:52:41Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2023-08-15T22:11:49Z","nvd_published_at":"2014-07-11T14:55:00Z","cwe_ids":["CWE-338"],"severity":"MODERATE"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2014-3503"},{"type":"WEB","url":"https://github.com/apache/syncope/commit/8e0045925a387ee211832c7e0709dd418cda1ad3"},{"type":"WEB","url":"https://syncope.apache.org/security.html#cve-2014-3503-insecure-random-implementations-used-to-generate-p"},{"type":"WEB","url":"https://web.archive.org/web/20140728093808/http://www.securityfocus.com/bid/68431"},{"type":"WEB","url":"https://web.archive.org/web/20201207014021/http://www.securityfocus.com/archive/1/532669/100/0/threaded"},{"type":"WEB","url":"http://packetstormsecurity.com/files/127375/Apache-Syncope-Insecure-Password-Generation.html"},{"type":"WEB","url":"http://svn.apache.org/viewvc?view=revision&revision=r1596537"}],"affected":[{"package":{"name":"org.apache.syncope:syncope","ecosystem":"Maven","purl":"pkg:maven/org.apache.syncope/syncope"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.1.0"},{"fixed":"1.1.8"}]}],"versions":["1.1.0","1.1.1","1.1.2","1.1.3","1.1.4","1.1.5","1.1.6","1.1.7"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-4c72-mrhf-23cg/GHSA-4c72-mrhf-23cg.json"}}],"schema_version":"1.9.0"}