7.5

CVE-2023-30797

Insecure Random Generation in Netflix Lemur

Netflix Lemur before version 1.3.2 used insufficiently random values when generating default credentials. The insufficiently random values may allow an attacker to guess the credentials and gain access to resources managed by Lemur.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
NetflixLemur Version < 1.3.2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.78% 0.512
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
134c704f-9b21-4f2e-91b3-4a467353bcc0 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
disclosure@vulncheck.com 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CWE-330 Use of Insufficiently Random Values

The product uses insufficiently random numbers or values in a security context that depends on unpredictable numbers.

https://github.com/Netflix/lemur/commit/666d853212174ee7f4e6f8b3b4b389ede1872238
Patch
https://github.com/Netflix/lemur/security/advisories/GHSA-5fqv-mpj8-h7gm
Vendor Advisory
https://github.com/Netflix/security-bulletins/blob/master/advisories/nflx-2023-001.md
Vendor Advisory
https://vulncheck.com/advisories/netflix-lemur-weak-rng
Third Party Advisory