QID 995992
Date Published: 2023-11-20
QID 995992: Python (Pip) Security Update for pypinksign (GHSA-fxff-wxxv-c2jc)
PyPinkSign v0.5.1 uses a non-random or static IV for Cipher Block Chaining (CBC) mode in AES encryption. This vulnerability can lead to the disclosure of information and communications.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-fxff-wxxv-c2jc for updates and patch information.
Vendor References
- GHSA-fxff-wxxv-c2jc -
github.com/advisories/GHSA-fxff-wxxv-c2jc
CVEs related to QID 995992
Software Advisories
| Advisory ID | Software | Component | Link |
|---|