Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-22376

Опубликовано: 03 янв. 2025
Источник: redhat
CVSS3: 4.8

Описание

In Net::OAuth::Client in the Net::OAuth package before 0.29 for Perl, the default nonce is a 32-bit integer generated from the built-in rand() function, which is not cryptographically strong.

A flaw was found in perl-Net-OAuth. This vulnerability allows predictable nonce generation via insufficient cryptographic strength.

Отчет

This vulnerability doesn't affect any supported Red Hat product.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-338
https://bugzilla.redhat.com/show_bug.cgi?id=2335488perl-Net-OAuth: perl-Net-OAuth: Predictable nonce generation due to insufficient cryptographic strength

4.8 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 1 года назад

In Net::OAuth::Client in the Net::OAuth package before 0.29 for Perl, the default nonce is a 32-bit integer generated from the built-in rand() function, which is not cryptographically strong.

CVSS3: 5.3
nvd
больше 1 года назад

In Net::OAuth::Client in the Net::OAuth package before 0.29 for Perl, the default nonce is a 32-bit integer generated from the built-in rand() function, which is not cryptographically strong.

CVSS3: 5.3
debian
больше 1 года назад

In Net::OAuth::Client in the Net::OAuth package before 0.29 for Perl, ...

CVSS3: 9.8
github
больше 1 года назад

In Net::OAuth::Client in the Net::OAuth package before 0.29 for Perl, the default nonce is a 32-bit integer generated from the built-in rand() function, which is not cryptographically strong.

4.8 Medium

CVSS3