{"id":"CVE-2014-3503","aliases":[],"url":"https://o3.security/vulnerability/CVE-2014-3503","summary":"Apache Syncope uses a weak PNRG","details":"Apache Syncope 1.1.x before 1.1.8 uses weak random values to generate passwords, which makes it easier for remote attackers to guess the password via a brute force attack.","published":"2022-05-14T02:52:41Z","modified":"2024-12-08T05:27:43.019566Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"org.apache.syncope:syncope","fixedVersion":"1.1.8"}],"fix":{"url":"https://github.com/apache/syncope/commit/8e0045925a387ee211832c7e0709dd418cda1ad3","label":"apache/syncope@8e00459"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2014-3503"},{"type":"WEB","url":"https://github.com/apache/syncope/commit/8e0045925a387ee211832c7e0709dd418cda1ad3"},{"type":"WEB","url":"https://syncope.apache.org/security.html#cve-2014-3503-insecure-random-implementations-used-to-generate-p"},{"type":"WEB","url":"https://web.archive.org/web/20140728093808/http://www.securityfocus.com/bid/68431"},{"type":"WEB","url":"https://web.archive.org/web/20201207014021/http://www.securityfocus.com/archive/1/532669/100/0/threaded"},{"type":"WEB","url":"http://packetstormsecurity.com/files/127375/Apache-Syncope-Insecure-Password-Generation.html"},{"type":"WEB","url":"http://svn.apache.org/viewvc?view=revision&revision=r1596537"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-12-08T05:27:43.019566Z"}}