Lucene search

K
osvGoogleOSV:GHSA-Q3JG-4C82-J4XH
HistoryNov 29, 2018 - 9:30 p.m.

Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) in Pivotal CredHub Service Broker

2018-11-2921:30:30
Google
osv.dev
7

0.001 Low

EPSS

Percentile

34.7%

Pivotal CredHub Service Broker, versions prior to 1.1.0, uses a guessable form of random number generation in creating service broker’s UAA client. A remote malicious user may guess the client secret and obtain or modify credentials for users of the CredHub Service.

0.001 Low

EPSS

Percentile

34.7%

Related for OSV:GHSA-Q3JG-4C82-J4XH