Skip to content

Conversation

@chgg-kboberg
Copy link

A clever user with access to enough voucher codes can recover the initial state of a long-running Java process, allowing them to forge codes. Seed recovery of Knuth's PRNG is a practical attack: https://hal.archives-ouvertes.fr/hal-02700791/document

Since voucher codes may have monetary value, I would recommend applying this relatively trivial patch.

A clever user with access to enough voucher codes can recover the initial state of a long-running Java process, allowing them to forge codes.  Seed recovery of Knuth's PRNG is a practical attack: https://hal.archives-ouvertes.fr/hal-02700791/document
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant