Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-4238

Опубликовано: 27 дек. 2022
Источник: redhat
CVSS3: 7
EPSS Низкий

Описание

Randomly-generated alphanumeric strings contain significantly less entropy than expected. The RandomAlphaNumeric and CryptoRandomAlphaNumeric functions always return strings containing at least one digit from 0 to 9. This significantly reduces the amount of entropy in short strings generated by these functions.

A flaw was found in goutils where randomly generated alphanumeric strings contain significantly less entropy than expected. Both the RandomAlphaNumeric and CryptoRandomAlphaNumeric functions always return strings containing at least one digit from 0 to 9. This issue significantly reduces the amount of entropy generated in short strings by these functions.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
cert-manager Operator for Red Hat OpenShiftcert-manager/jetstack-cert-manager-rhel9Not affected
Cryostat 2cryostat/cryostat-rhel8-operatorNot affected
Logging Subsystem for Red Hat OpenShiftopenshift-logging/logging-loki-rhel9Not affected
Logging Subsystem for Red Hat OpenShiftopenshift-logging/lokistack-gateway-rhel8Not affected
OpenShift Developer Tools and ServiceshelmAffected
OpenShift Developer Tools and Servicesjenkins-operator-containerAffected
OpenShift Serverlessopenshift-serverless-1/client-kn-rhel8Fix deferred
OpenShift Serverlessopenshift-serverless-1/ingress-rhel8-operatorFix deferred
OpenShift Serverlessopenshift-serverless-1-knative-client-plugin-event-sender-rhel8-containerFix deferred
OpenShift Serverlessopenshift-serverless-1/serving-queue-rhel8Fix deferred

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-331
https://bugzilla.redhat.com/show_bug.cgi?id=2156729goutils: RandomAlphaNumeric and CryptoRandomAlphaNumeric are not as random as they should be

EPSS

Процентиль: 68%
0.01319
Низкий

7 High

CVSS3

Связанные уязвимости

CVSS3: 9.1
ubuntu
больше 3 лет назад

Randomly-generated alphanumeric strings contain significantly less entropy than expected. The RandomAlphaNumeric and CryptoRandomAlphaNumeric functions always return strings containing at least one digit from 0 to 9. This significantly reduces the amount of entropy in short strings generated by these functions.

CVSS3: 9.1
nvd
больше 3 лет назад

Randomly-generated alphanumeric strings contain significantly less entropy than expected. The RandomAlphaNumeric and CryptoRandomAlphaNumeric functions always return strings containing at least one digit from 0 to 9. This significantly reduces the amount of entropy in short strings generated by these functions.

CVSS3: 9.1
msrc
6 месяцев назад

Insufficient randomness in github.com/Masterminds/goutils

CVSS3: 9.1
debian
больше 3 лет назад

Randomly-generated alphanumeric strings contain significantly less ent ...

github
около 5 лет назад

RandomAlphaNumeric and CryptoRandomAlphaNumeric are not as random as they should be

EPSS

Процентиль: 68%
0.01319
Низкий

7 High

CVSS3