Description
text/impl/DefaultTextCreator.java, text/impl/ChineseTextProducer.java, and text/impl/FiveLetterFirstNameTextCreator.java in kaptcha 2.3.2 use the Random (rather than SecureRandom) function for generating CAPTCHA values, which makes it easier for remote attackers to bypass intended access restrictions via a brute-force approach.
Remediation
References
https://github.com/penggle/kaptcha/issues/3
Related Vulnerabilities
CVE-2021-4245 Vulnerability in maven package org.webjars.npm:rfc6902
CVE-2019-3894 Vulnerability in maven package org.wildfly:wildfly-ee
CVE-2021-41084 Vulnerability in maven package org.http4s:http4s-server_3
CVE-2019-1010266 Vulnerability in maven package org.fujion.webjars:lodash
CVE-2022-30500 Vulnerability in maven package com.jflyfox:jflyfox_jfinal