A flaw was found in github.com/satori/go.uuid in versions from commit 0ef6afb2f6cdd6cdaeee3885a95099c63f18fc8c to d91630c8510268e75203009fe7daf2b8e1d60c45. Due to insecure randomness in the g.rand.Read function the generated UUIDs are predictable for an attacker.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-0607 | A flaw was found in github.com/satori/go.uuid in versions from commit 0ef6afb2f6cdd6cdaeee3885a95099c63f18fc8c to d91630c8510268e75203009fe7daf2b8e1d60c45. Due to insecure randomness in the g.rand.Read function the generated UUIDs are predictable for an attacker. |
Github GHSA |
GHSA-33m6-q9v5-62r7 | go.uuid has Predictable UUID Identifiers |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 11 Oct 2024 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Satori
Satori uuid |
|
| CPEs | cpe:2.3:a:satori:uuid:-:*:*:*:*:go:*:* | |
| Vendors & Products |
Go.uuid Project
Go.uuid Project go.uuid |
Satori
Satori uuid |
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-03T17:01:07.411Z
Reserved: 2021-05-05T00:00:00.000Z
Link: CVE-2021-3538
No data.
Status : Modified
Published: 2021-06-02T14:15:09.993
Modified: 2024-11-21T06:21:47.577
Link: CVE-2021-3538
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA