7.3.0
9 years ago
25 days ago
Known vulnerabilities in the org.apereo.cas:cas-server-support-oidc package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
org.apereo.cas:cas-server-support-oidc is a package that allows allows CAS to act as an OpenId Connect Provider (OP). Affected versions of this package are vulnerable to Insecure Randomness. A insecure source of randomness is used to generate all of its random values as it relies upon apache commons lang3 How to fix Insecure Randomness? Upgrade | [,6.1.0-RC5) |