Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rv8h-p43r-4x5r

Опубликовано: 17 мая 2022
Источник: github
Github: Прошло ревью
CVSS4: 6.3
CVSS3: 3.7

Описание

SimpleGeo python-oauth2 vulnerable to the use of Insufficiently Random Values to generate nonces

The (1) make_nonce, (2) generate_nonce, and (3) generate_verifier functions in SimpleGeo python-oauth2 uses weak random numbers to generate nonces, which makes it easier for remote attackers to guess the nonce via a brute force attack.

Пакеты

Наименование

oauth2

pip
Затронутые версииВерсия исправления

< 1.9rc1

1.9rc1

EPSS

Процентиль: 44%
0.00213
Низкий

6.3 Medium

CVSS4

3.7 Low

CVSS3

Дефекты

CWE-330

Связанные уязвимости

ubuntu
больше 11 лет назад

The (1) make_nonce, (2) generate_nonce, and (3) generate_verifier functions in SimpleGeo python-oauth2 uses weak random numbers to generate nonces, which makes it easier for remote attackers to guess the nonce via a brute force attack.

redhat
почти 13 лет назад

The (1) make_nonce, (2) generate_nonce, and (3) generate_verifier functions in SimpleGeo python-oauth2 uses weak random numbers to generate nonces, which makes it easier for remote attackers to guess the nonce via a brute force attack.

nvd
больше 11 лет назад

The (1) make_nonce, (2) generate_nonce, and (3) generate_verifier functions in SimpleGeo python-oauth2 uses weak random numbers to generate nonces, which makes it easier for remote attackers to guess the nonce via a brute force attack.

debian
больше 11 лет назад

The (1) make_nonce, (2) generate_nonce, and (3) generate_verifier func ...

EPSS

Процентиль: 44%
0.00213
Низкий

6.3 Medium

CVSS4

3.7 Low

CVSS3

Дефекты

CWE-330