Get ahead
VMware offers training and certification to turbo-charge your progress.
Learn moreSpring Security versions 4.2.x prior to 4.2.12, 5.0.x prior to 5.0.12, and 5.1.x prior to 5.1.5 contain an insecure randomness vulnerability when using SecureRandomFactoryBean#setSeed to configure a SecureRandom instance. In order to be impacted, an honest application must provide a seed and make the resulting random material available to an attacker for inspection.
Users of affected versions should apply the following mitigation:
This issue was identified and responsibly reported by Thijs Alkemade.
2019-04-02: Initial vulnerability report published.
To report a security vulnerability for a project within the Spring portfolio, see the Security Policy