Описание
Pivotal CredHub Service Broker, versions prior to 1.1.0, uses a guessable form of random number generation in creating service broker's UAA client. A remote malicious user may guess the client secret and obtain or modify credentials for users of the CredHub Service.
Ссылки
- Third Party AdvisoryVDB Entry
- MitigationVendor Advisory
- Third Party AdvisoryVDB Entry
- MitigationVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.1.0 (исключая)
cpe:2.3:a:pivotal_software:credhub_service_broker:*:*:*:*:*:*:*:*
EPSS
Процентиль: 57%
0.00357
Низкий
8.1 High
CVSS3
8.1 High
CVSS3
5.5 Medium
CVSS2
Дефекты
CWE-338
Связанные уязвимости
CVSS3: 8.1
github
около 7 лет назад
Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) in Pivotal CredHub Service Broker
EPSS
Процентиль: 57%
0.00357
Низкий
8.1 High
CVSS3
8.1 High
CVSS3
5.5 Medium
CVSS2
Дефекты
CWE-338