AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2019-3795

MEDIUM · CVSS 5.3 EPSS 1.88%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2019-04-09 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2019-3795
Severity
MEDIUM
CVSS
5.3
EPSS
1.88%

Original NVD Description

Spring Security versions 4.2.x prior to 4.2.12, 5.0.x prior to 5.0.12, and 5.1.x prior to 5.1.5 contain an insecure randomness vulnerability when using SecureRandomFactoryBean#setSeed to configure a SecureRandom instance. In order to be impacted, an honest application must provide a seed and make the resulting random material available to an attacker for inspection.