|
|
| |
|
| |
plexus-cipher: insufficiently random salt
| Package(s): | plexus-cipher |
CVE #(s): | |
| Created: | December 6, 2012 |
Updated: | December 12, 2012 |
| Description: |
getSalt() falls back to Random (seeded by the current time) instead of SecureRandom.
These bugs just decreases the randomness of the salt/IV, so they may not actually result in an exploitable security vulnerability. But that depends on how this class is used.
See the Red Hat bugzilla for details. |
| Alerts: |
|
( Log in to post comments)
|
|
|