Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2019-3795

21
FAUCET Score

CVE-2019-3795 is an insecure randomness vulnerability affecting Spring Security versions 4.2.x prior to 4.2.12, 5.0.x prior to 5.0.12, and 5.1.x prior to 5.1.5, specifically when SecureRandomFactoryBean#setSeed is used with a provided seed. This vulnerability is rated Medium severity (CVSS 5.3) due to its network-based attack vector and low attack complexity, potentially leading to information disclosure if an attacker can inspect the resulting random material. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage, indicating a low current threat landscape.

Impacted Technologies

VendorProductVersion(s)CPE
>= 4.2.0, < 4.2.12CPE matchmatch criteria
cpe:2.3:a:vmware:spring_security:*:*:*:*:*:*:*:*
>= 5.0.0, < 5.0.12CPE matchmatch criteria
cpe:2.3:a:vmware:spring_security:*:*:*:*:*:*:*:*
>= 5.1.0, < 5.1.5CPE matchmatch criteria
cpe:2.3:a:vmware:spring_security:*:*:*:*:*:*:*:*
8.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.0

3.8LOW

CVSS:3.0/AV:P/AC:H/PR:H/UI:R/S:U/C:N/I:H/A:N

Attack Vector
PHYSICAL
Attack Complexity
HIGH
Privileges Required
HIGH
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
HIGH
Availability Impact
NONE
Exploitability Score
0.1
Impact Score
3.6
CvssVersion
3.0

Exploit Intelligence

EPSS Score
1.88%
Probability of exploitation in next 30 days
EPSS Percentile
77.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0188 is in the 65th percentile among its peer group of 23,723 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (3)

redhatvendor investigatingvia redhat_api
Product: Red Hat Fuse 7Fixed in: spring-security-core
redhatend of lifevia redhat_api
Product: Red Hat OpenStack Platform 10 (Newton)Fixed in: opendaylight
redhatend of lifevia redhat_api
Product: Red Hat OpenStack Platform 9 (Mitaka)Fixed in: opendaylight

Vendor Advisories (2)

mavenGHSA-v2r2-7qm7-jj6vmedium

Spring Security uses insufficiently random values

Apr 16, 2019
redhatCVE-2019-3795Low

spring-security-core: Insecure randomness when using a secureRandom instance constructed by Spring Security

Apr 2, 2019

References

lists.debian.org / debian-lts-announce/2019/05/msg00026.html
Mailing ListThird Party Advisory
pivotal.io / security/cve-2019-3795
Vendor Advisory
securityfocus.com / bid/107802
Third Party AdvisoryVDB Entry