Lucene search

K
osvGoogleOSV:GHSA-GGFX-H9XJ-5V9C
HistoryMay 19, 2022 - 12:00 a.m.

Insecure PRNG use in random_password_generator

2022-05-1900:00:40
Google
osv.dev
10
random_password_generator
ruby
kernel#rand
password prediction
software

EPSS

0.002

Percentile

60.0%

The random_password_generator (aka RandomPasswordGenerator) gem through 1.0.0 for Ruby uses Kernel#rand to generate passwords, which, due to its cyclic nature, can facilitate password prediction.

EPSS

0.002

Percentile

60.0%

Related for OSV:GHSA-GGFX-H9XJ-5V9C