CVE-2019-10908

In Airsonic 10.2.1, RecoverController.java generates passwords via org.apache.commons.lang.RandomStringUtils, which uses java.util.Random internally. This PRNG has a 48-bit seed that can easily be bruteforced, leading to trivial privilege escalation attacks.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:airsonic_project:airsonic:10.2.1:*:*:*:*:*:*:*

Information

Published : 2019-04-07 07:29

Updated : 2021-07-21 04:39


NVD link : CVE-2019-10908

Mitre link : CVE-2019-10908


JSON object : View

CWE
CWE-335

Incorrect Usage of Seeds in Pseudo-Random Number Generator (PRNG)

Advertisement

dedicated server usa

Products Affected

airsonic_project

  • airsonic