Use of Predictable Algorithm in Random Number Generator in pkp/pkp-lib
CVE-2023-4695

9.6CRITICAL

Key Information:

Vendor

Pkp

Vendor
CVE Published:
1 September 2023

What is CVE-2023-4695?

A vulnerability has been identified in PKP Lib due to the use of a predictable algorithm in its random number generator. This weakness could potentially lead to the exposure of sensitive data or operations within applications utilizing the affected versions. Developers and system administrators are urged to update to version 3.3.0-16 or later to mitigate any associated risks.

Affected Version(s)

pkp/pkp-lib < 3.3.0-16

References

CVSS V3.1

Score:
9.6
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.