CVE-2019-10755: PAC4J
Medium severity, CVSS 4.9. EPSS: 1.1% chance of exploitation in the next 30 days.
The SAML identifier generated within SAML2Utils.java was found to make use of the apache commons-lang3 RandomStringUtils class which makes them predictable due to RandomStringUtils PRNG's algorithm not being cryptographically strong. This issue only affects the 3.X release of pac4j-saml.
Affected products
- PAC4J PAC4J: from 3.0.0, up to and including 3.8.2
Published 2019-09-23. Last modified 2026-06-17.