CVE-2019-25061
Summary
| CVE | CVE-2019-25061 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-05-18 11:15:00 UTC |
| Updated | 2022-05-26 18:43:00 UTC |
| Description | The random_password_generator (aka RandomPasswordGenerator) gem through 1.0.0 for Ruby uses Kernel#rand to generate passwords, which, due to its cyclic nature, can facilitate password prediction. |
Risk And Classification
Problem Types: CWE-335
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Random Password Generator Project | Random Password Generator | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| random_password_generator/random_password_generator.rb at 2855e8d7d8803dbb580ddd6cf13846394eb4530e · bvsatyaram/random_password_generator · GitHub | MISC | github.com | |
| Security of rand in ruby compared to other methods - Stack Overflow | MISC | stackoverflow.com | |
| Class: Random (Ruby 3.1.2) | MISC | ruby-doc.org | |
| Use SecureRandom by jodawill · Pull Request #1 · bvsatyaram/random_password_generator · GitHub | MISC | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.