Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories: GSA_kwCzR0hTQS1taGhmLXZnd2gtZnc5aM4AAwLn

Passeo uses insecure random number generator

Impact

Everyone below v1.0.5 is impacted by this flaw, of confidentiality being at risk due to the password(s) being easily able to be guessed with Passeo's use of the random library. It is recommended to change any passwords made with Passeo before v1.0.5 and upgrade to v1.0.5, and v1.0.5 patches this with the secrets library.

Workarounds

No current workaround available than updating to v1.0.5.

Permalink: https://github.com/advisories/GHSA-mhhf-vgwh-fw9h
JSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1taGhmLXZnd2gtZnc5aM4AAwLn
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Moderate
Classification: General
Published: over 1 year ago
Updated: 12 months ago


CVSS Score: 5.9
CVSS vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

Identifiers: GHSA-mhhf-vgwh-fw9h, CVE-2022-23472
References: Repository: https://github.com/ArjunSharda/Passeo
Blast Radius: 1.0

Affected Packages

pypi:Passeo
Dependent packages: 1
Dependent repositories: 0
Downloads: 85 last month
Affected Version Ranges: < 1.0.5
Fixed in: 1.0.5
All affected versions: 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.0.4
All unaffected versions: 1.0.5, 1.0.6, 1.0.7, 1.0.8, 1.0.9, 1.1.0, 1.1.1, 1.1.2, 1.1.3