Vulnerabilities > CVE-2021-3538 - Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) vulnerability in Go.Uuid Project Go.Uuid
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
PARTIAL Integrity impact
PARTIAL Availability impact
PARTIAL Summary
A flaw was found in github.com/satori/go.uuid in versions from commit 0ef6afb2f6cdd6cdaeee3885a95099c63f18fc8c to d91630c8510268e75203009fe7daf2b8e1d60c45. Due to insecure randomness in the g.rand.Read function the generated UUIDs are predictable for an attacker.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |