Vulnerabilities > CVE-2021-4238 - Insufficient Entropy vulnerability in Goutils Project Goutils 1.0.0/1.0.1/1.1.0
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
HIGH Integrity impact
NONE Availability impact
HIGH Summary
Randomly-generated alphanumeric strings contain significantly less entropy than expected. The RandomAlphaNumeric and CryptoRandomAlphaNumeric functions always return strings containing at least one digit from 0 to 9. This significantly reduces the amount of entropy in short strings generated by these functions.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 3 |