A flaw was found in github.com/satori/go.uuid in versions from commit 0ef6afb2f6cdd6cdaeee3885a95099c63f18fc8c to d91630c8510268e75203009fe7daf2b8e1d60c45. Due to insecure randomness in the g.rand.Read function the generated UUIDs are predictable for an attacker.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 11 Oct 2024 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Satori
Satori uuid
CPEs cpe:2.3:a:go.uuid_project:go.uuid:*:*:*:*:*:*:*:* cpe:2.3:a:satori:uuid:-:*:*:*:*:go:*:*
Vendors & Products Go.uuid Project
Go.uuid Project go.uuid
Satori
Satori uuid

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2024-08-03T17:01:07.411Z

Reserved: 2021-05-05T00:00:00

Link: CVE-2021-3538

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-06-02T14:15:09.993

Modified: 2024-11-21T06:21:47.577

Link: CVE-2021-3538

cve-icon Redhat

Severity : Moderate

Publid Date: 2018-03-24T00:00:00Z

Links: CVE-2021-3538 - Bugzilla

cve-icon OpenCVE Enrichment

No data.