Apache Syncope 1.1.x before 1.1.8 uses weak random values to generate passwords, which makes it easier for remote attackers to guess the password via a brute force attack.
{
"nvd_published_at": "2014-07-11T14:55:00Z",
"cwe_ids": [
"CWE-338"
],
"github_reviewed_at": "2023-08-15T22:11:49Z",
"severity": "MODERATE",
"github_reviewed": true
}