Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2013-4347

Опубликовано: 24 апр. 2013
Источник: redhat
CVSS2: 4.3
EPSS Низкий

Описание

The (1) make_nonce, (2) generate_nonce, and (3) generate_verifier functions in SimpleGeo python-oauth2 uses weak random numbers to generate nonces, which makes it easier for remote attackers to guess the nonce via a brute force attack.

It was found that python-oauth2 did not properly generate random values for use in nonces. An attacker able to capture network traffic of a website using OAuth2 authentication could use this flaw to conduct replay attacks against that website.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
CloudForms Management Engine 5python-oauth2Not affected
Red Hat OpenStack Platform 4python-oauth2Will not fix
RHUI for RHEL 6python-oauth2Will not fix
Red Hat Satellite 6.1aopallianceFixedRHSA-2015:159212.08.2015
Red Hat Satellite 6.1apache-commons-codec-eap6FixedRHSA-2015:159212.08.2015
Red Hat Satellite 6.1apache-mime4jFixedRHSA-2015:159212.08.2015
Red Hat Satellite 6.1atinjectFixedRHSA-2015:159212.08.2015
Red Hat Satellite 6.1bouncycastleFixedRHSA-2015:159212.08.2015
Red Hat Satellite 6.1c3p0FixedRHSA-2015:159212.08.2015
Red Hat Satellite 6.1candlepinFixedRHSA-2015:159212.08.2015

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-338
https://bugzilla.redhat.com/show_bug.cgi?id=1007758python-oauth2: Uses poor PRNG in nonce

EPSS

Процентиль: 44%
0.00213
Низкий

4.3 Medium

CVSS2

Связанные уязвимости

ubuntu
больше 11 лет назад

The (1) make_nonce, (2) generate_nonce, and (3) generate_verifier functions in SimpleGeo python-oauth2 uses weak random numbers to generate nonces, which makes it easier for remote attackers to guess the nonce via a brute force attack.

nvd
больше 11 лет назад

The (1) make_nonce, (2) generate_nonce, and (3) generate_verifier functions in SimpleGeo python-oauth2 uses weak random numbers to generate nonces, which makes it easier for remote attackers to guess the nonce via a brute force attack.

debian
больше 11 лет назад

The (1) make_nonce, (2) generate_nonce, and (3) generate_verifier func ...

CVSS3: 3.7
github
больше 3 лет назад

SimpleGeo python-oauth2 vulnerable to the use of Insufficiently Random Values to generate nonces

EPSS

Процентиль: 44%
0.00213
Низкий

4.3 Medium

CVSS2

Уязвимость CVE-2013-4347