Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-4238

Опубликовано: 27 дек. 2022
Источник: redhat
CVSS3: 7
EPSS Низкий

Описание

Randomly-generated alphanumeric strings contain significantly less entropy than expected. The RandomAlphaNumeric and CryptoRandomAlphaNumeric functions always return strings containing at least one digit from 0 to 9. This significantly reduces the amount of entropy in short strings generated by these functions.

A flaw was found in goutils where randomly generated alphanumeric strings contain significantly less entropy than expected. Both the RandomAlphaNumeric and CryptoRandomAlphaNumeric functions always return strings containing at least one digit from 0 to 9. This issue significantly reduces the amount of entropy generated in short strings by these functions.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
cert-manager Operator for Red Hat OpenShiftcert-manager/jetstack-cert-manager-rhel9Not affected
Cryostat 2cryostat-tech-preview/cryostat-rhel8-operatorNot affected
Logging Subsystem for Red Hat OpenShiftopenshift-logging/logging-loki-rhel8Not affected
Logging Subsystem for Red Hat OpenShiftopenshift-logging/lokistack-gateway-rhel9Not affected
OpenShift Developer Tools and ServiceshelmAffected
OpenShift Developer Tools and Servicesjenkins-operator-containerAffected
OpenShift Serverlessopenshift-serverless-1/client-kn-rhel8Fix deferred
OpenShift Serverlessopenshift-serverless-1/ingress-rhel8-operatorFix deferred
OpenShift Serverlessopenshift-serverless-1-knative-client-plugin-event-sender-rhel8-containerFix deferred
OpenShift Serverlessopenshift-serverless-1/serving-queue-rhel8Fix deferred

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-331
https://bugzilla.redhat.com/show_bug.cgi?id=2156729goutils: RandomAlphaNumeric and CryptoRandomAlphaNumeric are not as random as they should be

EPSS

Процентиль: 57%
0.00348
Низкий

7 High

CVSS3

Связанные уязвимости

CVSS3: 9.1
ubuntu
около 3 лет назад

Randomly-generated alphanumeric strings contain significantly less entropy than expected. The RandomAlphaNumeric and CryptoRandomAlphaNumeric functions always return strings containing at least one digit from 0 to 9. This significantly reduces the amount of entropy in short strings generated by these functions.

CVSS3: 9.1
nvd
около 3 лет назад

Randomly-generated alphanumeric strings contain significantly less entropy than expected. The RandomAlphaNumeric and CryptoRandomAlphaNumeric functions always return strings containing at least one digit from 0 to 9. This significantly reduces the amount of entropy in short strings generated by these functions.

CVSS3: 9.1
msrc
больше 1 года назад

Описание отсутствует

CVSS3: 9.1
debian
около 3 лет назад

Randomly-generated alphanumeric strings contain significantly less ent ...

github
больше 4 лет назад

RandomAlphaNumeric and CryptoRandomAlphaNumeric are not as random as they should be

EPSS

Процентиль: 57%
0.00348
Низкий

7 High

CVSS3