Описание
Pulp before 2.8.5 uses bash's $RANDOM in an unsafe way to generate passwords.
Pulp makes unsafe use of Bash's $RANDOM to generate a NSS DB password and seed resulting in insufficient randomness. An attacker could potentially guess the seed used given enough time and compute resources.
Дополнительная информация
Статус:
Moderate
Дефект:
CWE-330
https://bugzilla.redhat.com/show_bug.cgi?id=1330264pulp: Unsafe use of bash $RANDOM for NSS DB password and seed
EPSS
Процентиль: 79%
0.0198
Низкий
5.6 Medium
CVSS3
4.6 Medium
CVSS2
Связанные уязвимости
CVSS3: 7.5
nvd
около 9 лет назад
Pulp before 2.8.5 uses bash's $RANDOM in an unsafe way to generate passwords.
CVSS3: 7.5
github
больше 4 лет назад
Pulp before 2.8.5 uses bash's $RANDOM in an unsafe way to generate passwords.
EPSS
Процентиль: 79%
0.0198
Низкий
5.6 Medium
CVSS3
4.6 Medium
CVSS2