Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r4xg-4wrv-w72h

Опубликовано: 19 апр. 2023
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Duplicate Advisory: Lemur subject to insecure random generation

Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-5fqv-mpj8-h7gm. This link is maintained to preserve external references.

Original Description

Netflix Lemur before version 1.3.2 used insufficiently random values when generating default credentials. The insufficiently random values may allow an attacker to guess the credentials and gain access to resources managed by Lemur.

Пакеты

Наименование

lemur

pip
Затронутые версииВерсия исправления

< 1.3.2

1.3.2

7.5 High

CVSS3

Дефекты

CWE-330

7.5 High

CVSS3

Дефекты

CWE-330