Description
text/impl/DefaultTextCreator.java, text/impl/ChineseTextProducer.java, and text/impl/FiveLetterFirstNameTextCreator.java in kaptcha 2.3.2 use the Random (rather than SecureRandom) function for generating CAPTCHA values, which makes it easier for remote attackers to bypass intended access restrictions via a brute-force approach.
Remediation
References
https://github.com/penggle/kaptcha/issues/3
Related Vulnerabilities
CVE-2021-21290 Vulnerability in maven package io.netty:netty-handler
CVE-2018-12023 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind
CVE-2019-16569 Vulnerability in maven package org.jenkins-ci.plugins:mantis
CVE-2021-25642 Vulnerability in maven package org.apache.hadoop:hadoop-yarn-server-resourcemanager
CVE-2022-43417 Vulnerability in maven package org.jenkins-ci.plugins:katalon