Описание
WWW::OAuth 1.000 and earlier for Perl uses the rand() function as the default source of entropy, which is not cryptographically secure, for cryptographic functions.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | not-affected | |
| esm-apps/focal | needs-triage | |
| esm-apps/jammy | needs-triage | |
| esm-apps/noble | needs-triage | |
| esm-apps/resolute | not-affected | |
| jammy | needs-triage | |
| noble | needs-triage | |
| questing | not-affected | 1.003-1 |
| resolute | not-affected | |
| upstream | released | 1.001-1 |
Показывать по
10
Ссылки на источники
EPSS
Процентиль: 17%
0.00255
Низкий
7.3 High
CVSS3
Связанные уязвимости
CVSS3: 7.3
nvd
7 месяцев назад
WWW::OAuth 1.000 and earlier for Perl uses the rand() function as the default source of entropy, which is not cryptographically secure, for cryptographic functions.
CVSS3: 7.3
debian
7 месяцев назад
WWW::OAuth 1.000 and earlier for Perl uses the rand() function as the ...
CVSS3: 7.3
github
7 месяцев назад
WWW::OAuth 1.000 and earlier for Perl uses the rand() function as the default source of entropy, which is not cryptographically secure, for cryptographic functions.
EPSS
Процентиль: 17%
0.00255
Низкий
7.3 High
CVSS3