Standard Random Number Generator used in BaseCluster is not safe

XMLWordPrintableJSON

    • Type: Task
    • Resolution: Works as Designed
    • Priority: Critical - P2
    • None
    • Affects Version/s: None
    • Component/s: None
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None

      Hi,

      We got the below issue when we ran Veracode testing our code.

      Insufficient Entropy (CWE ID 331)

      Class : BaseCluster.java
      line no: 336

      We are using mongo-java-driver-3.4.1.jar

      As per the issue, it seems standard random number generator has been used when a more secure cryptograpic generator should have been used.

      Is this a false positive from Veracode and can it be safely ignored.

      If not, can you please let us know if it can be mitigated in java driver code.

      Thanks,
      lauriep

            Assignee:
            Unassigned
            Reporter:
            Laurie paul
            None
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

              Created:
              Updated:
              Resolved: