2 results (0.016 seconds)

CVSS: 7.5EPSS: 0%CPEs: 1EXPL: 0

Netflix Lemur before version 1.3.2 used insufficiently random values when generating default credentials. The insufficiently random values may allow an attacker to guess the credentials and gain access to resources managed by Lemur. • https://github.com/Netflix/lemur/commit/666d853212174ee7f4e6f8b3b4b389ede1872238 https://github.com/Netflix/lemur/security/advisories/GHSA-5fqv-mpj8-h7gm https://github.com/Netflix/security-bulletins/blob/master/advisories/nflx-2023-001.md https://vulncheck.com/advisories/netflix-lemur-weak-rng • CWE-330: Use of Insufficiently Random Values •

CVSS: 7.5EPSS: 0%CPEs: 1EXPL: 0

Lemur 0.1.4 does not use sufficient entropy in its IV when encrypting AES in CBC mode. Lemur 0.1.4 no emplea la suficiente entropía en su vector de inicialización cuando cifra AES en modo CBC. • http://www.openwall.com/lists/oss-security/2015/10/20/3 https://github.com/Netflix/lemur/issues/117 https://github.com/kvesteri/sqlalchemy-utils/issues/166 • CWE-331: Insufficient Entropy •