7.5

CVE-2019-25089

Morgawr Muon handler.clj random values

A vulnerability has been found in Morgawr Muon 0.1.1 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file src/muon/handler.clj. The manipulation leads to insufficiently random values. The attack can be launched remotely. Upgrading to version 0.2.0-indev is able to address this issue. The name of the patch is c09ed972c020f759110c707b06ca2644f0bacd7f. It is recommended to upgrade the affected component. The identifier VDB-216877 was assigned to this vulnerability.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Muon ProjectMuon Version0.1.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.65% 0.461
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
cna@vuldb.com 3.1 1.6 1.4
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
CWE-330 Use of Insufficiently Random Values

The product uses insufficiently random numbers or values in a security context that depends on unpredictable numbers.

https://github.com/Morgawr/Muon/commit/c09ed972c020f759110c707b06ca2644f0bacd7f
Patch
Third Party Advisory
https://github.com/Morgawr/Muon/issues/4
Patch
Third Party Advisory
Issue Tracking
https://vuldb.com/?ctiid.216877
Third Party Advisory
https://vuldb.com/?id.216877
Third Party Advisory