Ecosyste.ms: Advisories
An open API service providing security vulnerability metadata for many open source software ecosystems.
Security Advisories: GSA_kwCzR0hTQS1taGhmLXZnd2gtZnc5aM4AAwLn
Passeo uses insecure random number generator
Impact
Everyone below v1.0.5 is impacted by this flaw, of confidentiality being at risk due to the password(s) being easily able to be guessed with Passeo's use of the random
library. It is recommended to change any passwords made with Passeo before v1.0.5 and upgrade to v1.0.5, and v1.0.5 patches this with the secrets
library.
Workarounds
No current workaround available than updating to v1.0.5.
Permalink: https://github.com/advisories/GHSA-mhhf-vgwh-fw9hJSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1taGhmLXZnd2gtZnc5aM4AAwLn
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Moderate
Classification: General
Published: over 1 year ago
Updated: 12 months ago
CVSS Score: 5.9
CVSS vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Identifiers: GHSA-mhhf-vgwh-fw9h, CVE-2022-23472
References:
- https://github.com/ArjunSharda/Passeo/security/advisories/GHSA-mhhf-vgwh-fw9h
- https://nvd.nist.gov/vuln/detail/CVE-2022-23472
- https://github.com/ArjunSharda/Passeo/commit/8caa798b6bc4647dca59b2376204b6dc6176361a
- https://peps.python.org/pep-0506/
- https://github.com/advisories/GHSA-mhhf-vgwh-fw9h
Blast Radius: 1.0
Affected Packages
pypi:Passeo
Dependent packages: 1Dependent repositories: 0
Downloads: 85 last month
Affected Version Ranges: < 1.0.5
Fixed in: 1.0.5
All affected versions: 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.0.4
All unaffected versions: 1.0.5, 1.0.6, 1.0.7, 1.0.8, 1.0.9, 1.1.0, 1.1.1, 1.1.2, 1.1.3