Insufficient randomness in github.com/Masterminds/goutils
CVE-2021-4238
9.1CRITICAL
Key Information:
- Vendor
- CVE Published:
- 27 December 2022
What is CVE-2021-4238?
Randomly-generated alphanumeric strings contain significantly less entropy than expected. The RandomAlphaNumeric and CryptoRandomAlphaNumeric functions always return strings containing at least one digit from 0 to 9. This significantly reduces the amount of entropy in short strings generated by these functions.
Affected Version(s)
github.com/Masterminds/goutils 0 < 1.1.1