Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q3jg-4c82-j4xh

Опубликовано: 29 нояб. 2018
Источник: github
Github: Прошло ревью
CVSS3: 8.1

Описание

Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) in Pivotal CredHub Service Broker

Pivotal CredHub Service Broker, versions prior to 1.1.0, uses a guessable form of random number generation in creating service broker's UAA client. A remote malicious user may guess the client secret and obtain or modify credentials for users of the CredHub Service.

Пакеты

Наименование

org.springframework.credhub:spring-credhub-core

maven
Затронутые версииВерсия исправления

< 1.1.0

1.1.0

EPSS

Процентиль: 57%
0.00357
Низкий

8.1 High

CVSS3

Дефекты

CWE-338

Связанные уязвимости

CVSS3: 8.1
nvd
около 7 лет назад

Pivotal CredHub Service Broker, versions prior to 1.1.0, uses a guessable form of random number generation in creating service broker's UAA client. A remote malicious user may guess the client secret and obtain or modify credentials for users of the CredHub Service.

EPSS

Процентиль: 57%
0.00357
Низкий

8.1 High

CVSS3

Дефекты

CWE-338