Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-23472

Опубликовано: 06 дек. 2022
Источник: nvd
CVSS3: 5.9
CVSS3: 7.5
EPSS Низкий

Описание

Passeo is an open source python password generator. Versions prior to 1.0.5 rely on the python random library for random value selection. The python random library warns that it should not be used for security purposes due to its reliance on a non-cryptographically secure random number generator. As a result a motivated attacker may be able to guess generated passwords. This issue has been addressed in version 1.0.5. Users are advised to upgrade. There are no known workarounds for this vulnerability.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:passeo_project:passeo:*:*:*:*:*:python:*:*
Версия до 1.0.5 (исключая)

EPSS

Процентиль: 58%
0.00366
Низкий

5.9 Medium

CVSS3

7.5 High

CVSS3

Дефекты

CWE-338

Связанные уязвимости

CVSS3: 5.9
github
около 3 лет назад

Passeo uses insecure random number generator

EPSS

Процентиль: 58%
0.00366
Низкий

5.9 Medium

CVSS3

7.5 High

CVSS3

Дефекты

CWE-338