{"id":"GHSA-rc75-cf5c-mxvh","summary":"Use of Cryptographically Weak Pseudo-Random Number Generator in org.pac4j:pac4j-saml","details":"The SAML identifier generated within SAML2Utils.java was found to make use of the apache commons-lang3 RandomStringUtils class which makes them predictable due to RandomStringUtils PRNG's algorithm not being cryptographically strong. This issue only affects the 3.X release of pac4j-saml.","aliases":["CVE-2019-10755","SNYK-JAVA-ORGPAC4J-467407"],"modified":"2026-09-10T03:49:24.755445257Z","published":"2019-11-06T17:06:28Z","database_specific":{"cwe_ids":["CWE-338"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2019-11-05T19:56:04Z","nvd_published_at":"2019-09-23T23:15:00Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2019-10755"},{"type":"WEB","url":"https://github.com/pac4j/pac4j/commit/34d5b1028a2db201ee81ec51b52a782fe073f609"},{"type":"WEB","url":"https://snyk.io/vuln/SNYK-JAVA-ORGPAC4J-467407"}],"affected":[{"package":{"name":"org.pac4j:pac4j-saml","ecosystem":"Maven","purl":"pkg:maven/org.pac4j/pac4j-saml"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.8.2"}]}],"versions":["1.5.0","1.5.1","1.6.0","1.6.0-RC1","1.7.0","1.7.1","1.7.2","1.8.0","1.8.0-RC1","1.8.1","1.8.2","1.8.3","1.8.4","1.8.5","1.8.6","1.8.7","1.8.8","1.8.9","1.9.0","1.9.1","1.9.2","1.9.3","1.9.4","1.9.5","1.9.6","1.9.7","1.9.8","1.9.9","2.0.0","2.0.0-RC1","2.0.0-RC2","2.1.0","2.2.0","2.2.1","2.3.0","2.3.1","3.0.0","3.0.0-RC1","3.0.0-RC2","3.0.1","3.0.2","3.1.0","3.2.0","3.3.0","3.4.0","3.5.0","3.6.0","3.6.1","3.7.0","3.8.0","3.8.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/11/GHSA-rc75-cf5c-mxvh/GHSA-rc75-cf5c-mxvh.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"}]}