Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-48vv-2pmq-9fvv

Опубликовано: 23 июл. 2018
Источник: github
Github: Прошло ревью
CVSS4: 8.7
CVSS3: 7.5

Описание

Plone and Zope2 do not reseed pseudo-random number generator

Zope before 2.13.19, as used in Plone before 4.2.3 and 4.3 before beta 1, does not reseed the pseudo-random number generator (PRNG), which makes it easier for remote attackers to guess the value via unspecified vectors. NOTE: this issue was SPLIT from CVE-2012-5508 due to different vulnerability types (ADT2).

Пакеты

Наименование

Zope2

pip
Затронутые версииВерсия исправления

< 2.13.19

2.13.19

Наименование

Plone

pip
Затронутые версииВерсия исправления

>= 3.2.2, < 4.2.3

4.2.3

Наименование

Plone

pip
Затронутые версииВерсия исправления

>= 4.3a1, <= 4.3a2

4.3b1

EPSS

Процентиль: 60%
0.00403
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-336

Связанные уязвимости

ubuntu
больше 11 лет назад

Zope before 2.13.19, as used in Plone before 4.2.3 and 4.3 before beta 1, does not reseed the pseudo-random number generator (PRNG), which makes it easier for remote attackers to guess the value via unspecified vectors. NOTE: this issue was SPLIT from CVE-2012-5508 due to different vulnerability types (ADT2).

redhat
больше 13 лет назад

Zope before 2.13.19, as used in Plone before 4.2.3 and 4.3 before beta 1, does not reseed the pseudo-random number generator (PRNG), which makes it easier for remote attackers to guess the value via unspecified vectors. NOTE: this issue was SPLIT from CVE-2012-5508 due to different vulnerability types (ADT2).

nvd
больше 11 лет назад

Zope before 2.13.19, as used in Plone before 4.2.3 and 4.3 before beta 1, does not reseed the pseudo-random number generator (PRNG), which makes it easier for remote attackers to guess the value via unspecified vectors. NOTE: this issue was SPLIT from CVE-2012-5508 due to different vulnerability types (ADT2).

debian
больше 11 лет назад

Zope before 2.13.19, as used in Plone before 4.2.3 and 4.3 before beta ...

EPSS

Процентиль: 60%
0.00403
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-336