Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:35596
HistoryMay 19, 2022 - 3:54 a.m.

Information Disclosure

2022-05-1903:54:49
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
11
information disclosure
random_password_generator
insecure generation
rand functionality
guess password

EPSS

0.002

Percentile

60.0%

random_password_generator is vulnerable to information disclosure. The vulnerability exists due to the insecure random password generation in rand functionality in the generate function of random_password_generator.rb, allowing an attacker to guess the password.

EPSS

0.002

Percentile

60.0%