Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2r47-hhff-7qcp

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

cloud-init through 19.4 relies on Mersenne Twister for a random password, which makes it easier for attackers to predict passwords, because rand_str in cloudinit/util.py calls the random.choice function.

cloud-init through 19.4 relies on Mersenne Twister for a random password, which makes it easier for attackers to predict passwords, because rand_str in cloudinit/util.py calls the random.choice function.

EPSS

Процентиль: 31%
0.00116
Низкий

Дефекты

CWE-330

Связанные уязвимости

CVSS3: 5.5
ubuntu
около 6 лет назад

cloud-init through 19.4 relies on Mersenne Twister for a random password, which makes it easier for attackers to predict passwords, because rand_str in cloudinit/util.py calls the random.choice function.

CVSS3: 8.1
redhat
около 6 лет назад

cloud-init through 19.4 relies on Mersenne Twister for a random password, which makes it easier for attackers to predict passwords, because rand_str in cloudinit/util.py calls the random.choice function.

CVSS3: 5.5
nvd
около 6 лет назад

cloud-init through 19.4 relies on Mersenne Twister for a random password, which makes it easier for attackers to predict passwords, because rand_str in cloudinit/util.py calls the random.choice function.

CVSS3: 5.5
msrc
больше 5 лет назад

cloud-init through 19.4 relies on Mersenne Twister for a random password which makes it easier for attackers to predict passwords because rand_str in cloudinit/util.py calls the random.choice function.

CVSS3: 5.5
debian
около 6 лет назад

cloud-init through 19.4 relies on Mersenne Twister for a random passwo ...

EPSS

Процентиль: 31%
0.00116
Низкий

Дефекты

CWE-330