CVE-2023-30797
Summary
| CVE | CVE-2023-30797 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-04-19 20:15:00 UTC |
| Updated | 2023-05-01 19:55:00 UTC |
| Description | Netflix Lemur before version 1.3.2 used insufficiently random values when generating default credentials. The insufficiently random values may allow an attacker to guess the credentials and gain access to resources managed by Lemur. |
Risk And Classification
Problem Types: CWE-330
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Merge pull request from GHSA-5fqv-mpj8-h7gm · Netflix/lemur@666d853 · GitHub | MISC | github.com | |
| NFLX-2023-001 Insecure random generation · Advisory · Netflix/lemur · GitHub | MISC | github.com | |
| Insecure random generation in Netflix Lemur python app | VulnCheck Advisories | MISC | vulncheck.com | |
| security-bulletins/nflx-2023-001.md at master · Netflix/security-bulletins · GitHub | MISC | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.