Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-3538

Опубликовано: 02 июн. 2021
Источник: nvd
CVSS3: 9.8
CVSS2: 7.5
EPSS Низкий

Описание

A flaw was found in github.com/satori/go.uuid in versions from commit 0ef6afb2f6cdd6cdaeee3885a95099c63f18fc8c to d91630c8510268e75203009fe7daf2b8e1d60c45. Due to insecure randomness in the g.rand.Read function the generated UUIDs are predictable for an attacker.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:satori:uuid:-:*:*:*:*:go:*:*

EPSS

Процентиль: 63%
0.00457
Низкий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-338
CWE-338

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 4 лет назад

A flaw was found in github.com/satori/go.uuid in versions from commit 0ef6afb2f6cdd6cdaeee3885a95099c63f18fc8c to d91630c8510268e75203009fe7daf2b8e1d60c45. Due to insecure randomness in the g.rand.Read function the generated UUIDs are predictable for an attacker.

CVSS3: 9.8
redhat
почти 8 лет назад

A flaw was found in github.com/satori/go.uuid in versions from commit 0ef6afb2f6cdd6cdaeee3885a95099c63f18fc8c to d91630c8510268e75203009fe7daf2b8e1d60c45. Due to insecure randomness in the g.rand.Read function the generated UUIDs are predictable for an attacker.

CVSS3: 9.8
debian
больше 4 лет назад

A flaw was found in github.com/satori/go.uuid in versions from commit ...

CVSS3: 9.8
github
почти 3 года назад

go.uuid has Predictable UUID Identifiers

EPSS

Процентиль: 63%
0.00457
Низкий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-338
CWE-338