CVE Explorer
CVE-2025-62710
Sakai is a Collaboration and Learning Environment. Prior to versions 23.5 and 25.0, EncryptionUtilityServiceImpl initialized an AES256TextEncryptor password (serverSecretKey) using RandomStringUtils with the default java.util.Random. java.util.Random is a non‑cryptographic PRNG and can be predicted from limited state/seed information (e.g., start time window), substantially reducing the effective search space of the generated key. An attacker who can obtain ciphertexts (e.g., exported or at‑rest
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"sakai","vendor":"sakaiproject","versions":[{"status":"affected","version":"< 23.5"},{"status":"affected","version":"< 25.0"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:6a5b139e1cd095c080d9b57bc9dcb39b89a1b9e22e96ae2fc2771a389bef419e · sha256:22bc9d4bcd7baa98… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":5.9,"baseSeverity":"MEDIUM","confidentialityImpact":"HIGH","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:6a5b139e1cd095c080d9b57bc9dcb39b89a1b9e22e96ae2fc2771a389bef419e · sha256:22bc9d4bcd7baa98… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-337","description":"CWE-337: Predictable Seed in Pseudo-Random Number Generator (PRNG)","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:6a5b139e1cd095c080d9b57bc9dcb39b89a1b9e22e96ae2fc2771a389bef419e · sha256:22bc9d4bcd7baa98… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"name":"https://github.com/sakaiproject/sakai/commit/bde070104b1de01f4a6458dca6d9e0880a0e3c04","tags":["x_refsource_MISC"],"url":"https://github.com/sakaiproject/sakai/commit/bde070104b1de01f4a6458dca6d9e0880a0e3c04"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:6a5b139e1cd095c080d9b57bc9dcb39b89a1b9e22e96ae2fc2771a389bef419e · sha256:22bc9d4bcd7baa98… · /containers/cna/references/1
{"name":"https://github.com/sakaiproject/sakai/security/advisories/GHSA-gr7h-xw4f-wh86","tags":["x_refsource_CONFIRM"],"url":"https://github.com/sakaiproject/sakai/security/advisories/GHSA-gr7h-xw4f-wh86"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:6a5b139e1cd095c080d9b57bc9dcb39b89a1b9e22e96ae2fc2771a389bef419e · sha256:22bc9d4bcd7baa98… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.