Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-3538

Опубликовано: 02 июн. 2021
Источник: debian
EPSS Низкий

Описание

A flaw was found in github.com/satori/go.uuid in versions from commit 0ef6afb2f6cdd6cdaeee3885a95099c63f18fc8c to d91630c8510268e75203009fe7daf2b8e1d60c45. Due to insecure randomness in the g.rand.Read function the generated UUIDs are predictable for an attacker.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
golang-github-satori-go.uuidnot-affectedpackage

Примечания

  • https://snyk.io/vuln/SNYK-GOLANG-GITHUBCOMSATORIGOUUID-72488

  • Possibly introduced by: https://github.com/satori/go.uuid/commit/0ef6afb2f6cdd6cdaeee3885a95099c63f18fc8c

  • Fixed by: https://github.com/satori/go.uuid/commit/d91630c8510268e75203009fe7daf2b8e1d60c45

  • https://github.com/satori/go.uuid/issues/73

EPSS

Процентиль: 63%
0.00457
Низкий

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 4 лет назад

A flaw was found in github.com/satori/go.uuid in versions from commit 0ef6afb2f6cdd6cdaeee3885a95099c63f18fc8c to d91630c8510268e75203009fe7daf2b8e1d60c45. Due to insecure randomness in the g.rand.Read function the generated UUIDs are predictable for an attacker.

CVSS3: 9.8
redhat
почти 8 лет назад

A flaw was found in github.com/satori/go.uuid in versions from commit 0ef6afb2f6cdd6cdaeee3885a95099c63f18fc8c to d91630c8510268e75203009fe7daf2b8e1d60c45. Due to insecure randomness in the g.rand.Read function the generated UUIDs are predictable for an attacker.

CVSS3: 9.8
nvd
больше 4 лет назад

A flaw was found in github.com/satori/go.uuid in versions from commit 0ef6afb2f6cdd6cdaeee3885a95099c63f18fc8c to d91630c8510268e75203009fe7daf2b8e1d60c45. Due to insecure randomness in the g.rand.Read function the generated UUIDs are predictable for an attacker.

CVSS3: 9.8
github
почти 3 года назад

go.uuid has Predictable UUID Identifiers

EPSS

Процентиль: 63%
0.00457
Низкий