-
Notifications
You must be signed in to change notification settings - Fork 173
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Improved: Improve use of RandomStringUtils where it's potentially use…
…d in an insecure way (OFBIZ-12854) This is related to CWE-338 and CVE-2019-16303 that don't concern OFBiz. Actually the password generated by the passport component is not more insecure than the ofbiz password used OOTB in many places. But it's somehow hidden (automated generation) and it's easy to randomise it better, still using only alphanumeric chars as currently. There are other uses of RandomStringUtils but they don't relate to passwords generation and are safely used. Thanks: Alessandro Albani who reported globally for all ASF projects
- Loading branch information
1 parent
b189871
commit 598ccb6
Showing
2 changed files
with
8 additions
and
4 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters