Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wj5x-c2v9-7wwr

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The SecureRandom.random_bytes function in lib/securerandom.rb in Ruby before 1.8.7-p352 and 1.9.x before 1.9.2-p290 relies on PID values for initialization, which makes it easier for context-dependent attackers to predict the result string by leveraging knowledge of random strings obtained in an earlier process with the same PID.

The SecureRandom.random_bytes function in lib/securerandom.rb in Ruby before 1.8.7-p352 and 1.9.x before 1.9.2-p290 relies on PID values for initialization, which makes it easier for context-dependent attackers to predict the result string by leveraging knowledge of random strings obtained in an earlier process with the same PID.

EPSS

Процентиль: 79%
0.0137
Низкий

Дефекты

CWE-20

Связанные уязвимости

ubuntu
около 14 лет назад

The SecureRandom.random_bytes function in lib/securerandom.rb in Ruby before 1.8.7-p352 and 1.9.x before 1.9.2-p290 relies on PID values for initialization, which makes it easier for context-dependent attackers to predict the result string by leveraging knowledge of random strings obtained in an earlier process with the same PID.

redhat
около 14 лет назад

The SecureRandom.random_bytes function in lib/securerandom.rb in Ruby before 1.8.7-p352 and 1.9.x before 1.9.2-p290 relies on PID values for initialization, which makes it easier for context-dependent attackers to predict the result string by leveraging knowledge of random strings obtained in an earlier process with the same PID.

nvd
около 14 лет назад

The SecureRandom.random_bytes function in lib/securerandom.rb in Ruby before 1.8.7-p352 and 1.9.x before 1.9.2-p290 relies on PID values for initialization, which makes it easier for context-dependent attackers to predict the result string by leveraging knowledge of random strings obtained in an earlier process with the same PID.

debian
около 14 лет назад

The SecureRandom.random_bytes function in lib/securerandom.rb in Ruby ...

oracle-oval
больше 13 лет назад

ELSA-2011-1581: ruby security, bug fix, and enhancement update (LOW)

EPSS

Процентиль: 79%
0.0137
Низкий

Дефекты

CWE-20