Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7rq2-v6rc-96jw

Опубликовано: 31 мар. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 9.1

Описание

Business::OnlinePayment::StoredTransaction versions through 0.01 for Perl uses an insecure secret key.

Business::OnlinePayment::StoredTransaction generates a secret key by using a MD5 hash of a single call to the built-in rand function, which is unsuitable for cryptographic use.

This key is intended for encrypting credit card transaction data.

Business::OnlinePayment::StoredTransaction versions through 0.01 for Perl uses an insecure secret key.

Business::OnlinePayment::StoredTransaction generates a secret key by using a MD5 hash of a single call to the built-in rand function, which is unsuitable for cryptographic use.

This key is intended for encrypting credit card transaction data.

EPSS

Процентиль: 15%
0.0005
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-338

Связанные уязвимости

CVSS3: 9.1
nvd
15 дней назад

Business::OnlinePayment::StoredTransaction versions through 0.01 for Perl uses an insecure secret key. Business::OnlinePayment::StoredTransaction generates a secret key by using a MD5 hash of a single call to the built-in rand function, which is unsuitable for cryptographic use. This key is intended for encrypting credit card transaction data.

EPSS

Процентиль: 15%
0.0005
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-338