Описание
A flaw was found in github.com/satori/go.uuid in versions from commit 0ef6afb2f6cdd6cdaeee3885a95099c63f18fc8c to d91630c8510268e75203009fe7daf2b8e1d60c45. Due to insecure randomness in the g.rand.Read function the generated UUIDs are predictable for an attacker.
A flaw was found in github.com/satori/go.uuid. Due to insecure randomness in the g.rand.Read function the generated UUIDs are predictable for an attacker.
Отчет
For OpenShift Virtualization, github.com/satori/go.uuid is referenced in some of the projects' go.sum files, however it is only used in ovs-cni-plugin-container, where a version including the fix for this flaw is used. An upstream fix has been pushed into the master branch [1], but new release was not published. [1] https://github.com/satori/go.uuid/commit/d91630c8510268e75203009fe7daf2b8e1d60c45
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Migration Toolkit for Containers | rhmtc/openshift-migration-controller-rhel8 | Not affected | ||
| Migration Toolkit for Containers | rhmtc/openshift-migration-registry-rhel8 | Not affected | ||
| Migration Toolkit for Containers | rhmtc/openshift-migration-velero-plugin-for-gcp-rhel8 | Not affected | ||
| Migration Toolkit for Containers | rhmtc/openshift-migration-velero-plugin-for-microsoft-azure-rhel8 | Not affected | ||
| Migration Toolkit for Containers | rhmtc/openshift-migration-velero-rhel8 | Not affected | ||
| Red Hat Advanced Cluster Management for Kubernetes 2 | rbac-query-proxy-container | Not affected | ||
| Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/acm-grafana-rhel8 | Not affected | ||
| Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/cert-policy-controller-rhel9 | Not affected | ||
| Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/cluster-curator-controller-rhel8 | Not affected | ||
| Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/clusterlifecycle-state-metrics-rhel8 | Not affected |
Показывать по
Дополнительная информация
Статус:
EPSS
9.8 Critical
CVSS3
Связанные уязвимости
A flaw was found in github.com/satori/go.uuid in versions from commit 0ef6afb2f6cdd6cdaeee3885a95099c63f18fc8c to d91630c8510268e75203009fe7daf2b8e1d60c45. Due to insecure randomness in the g.rand.Read function the generated UUIDs are predictable for an attacker.
A flaw was found in github.com/satori/go.uuid in versions from commit 0ef6afb2f6cdd6cdaeee3885a95099c63f18fc8c to d91630c8510268e75203009fe7daf2b8e1d60c45. Due to insecure randomness in the g.rand.Read function the generated UUIDs are predictable for an attacker.
A flaw was found in github.com/satori/go.uuid in versions from commit ...
EPSS
9.8 Critical
CVSS3