icon

We found results for “

CVE-2025-62710

Good to know:

icon
icon
icon

Date: October 22, 2025

Sakai is a Collaboration and Learning Environment. Prior to versions 23.5 and 25.0, EncryptionUtilityServiceImpl initialized an AES256TextEncryptor password (serverSecretKey) using RandomStringUtils with the default java.util.Random. java.util.Random is a non‑cryptographic PRNG and can be predicted from limited state/seed information (e.g., start time window), substantially reducing the effective search space of the generated key. An attacker who can obtain ciphertexts (e.g., exported or at‑rest strings protected by this service) and approximate the PRNG seed can feasibly reconstruct the serverSecretKey and decrypt affected data. SAK-49866 is patched in Sakai 23.5, 25.0, and trunk.

Severity Score

Severity Score

Weakness Type (CWE)

Predictable Seed in Pseudo-Random Number Generator (PRNG)

CWE-337

Top Fix

icon

Upgrade Version

Upgrade to version org.sakaiproject.kernel:sakai-kernel-impl:25.0;https://github.com/sakaiproject/sakai.git - 25.0

Learn More

CVSS v3.1

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): HIGH
Privileges Required (PR): NONE
User Interaction (UI): NONE
Scope (S): UNCHANGED
Confidentiality (C): HIGH
Integrity (I): NONE
Availability (A): NONE

Do you need more information?

Contact Us