Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6fcj-rv73-f37c

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

An issue was discovered in beta versions of the 1Password command-line tool prior to 0.5.5 and in beta versions of the 1Password SCIM bridge prior to 0.7.3. An insecure random number generator was used to generate various keys. An attacker with access to the user's encrypted data may be able to perform brute-force calculations of encryption keys and thus succeed at decryption.

An issue was discovered in beta versions of the 1Password command-line tool prior to 0.5.5 and in beta versions of the 1Password SCIM bridge prior to 0.7.3. An insecure random number generator was used to generate various keys. An attacker with access to the user's encrypted data may be able to perform brute-force calculations of encryption keys and thus succeed at decryption.

EPSS

Процентиль: 50%
0.00264
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-335

Связанные уязвимости

CVSS3: 9.8
nvd
больше 5 лет назад

An issue was discovered in beta versions of the 1Password command-line tool prior to 0.5.5 and in beta versions of the 1Password SCIM bridge prior to 0.7.3. An insecure random number generator was used to generate various keys. An attacker with access to the user's encrypted data may be able to perform brute-force calculations of encryption keys and thus succeed at decryption.

EPSS

Процентиль: 50%
0.00264
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-335