LTI 1.3 Tool Library is a library used for building IMS-certified LTI 1.3 tool providers in PHP. Prior to version 5.0, the function used to generate random nonces was not sufficiently cryptographically complex. Users should upgrade to version 5.0 to receive a patch. There are currently no known workarounds.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-6276 | LTI 1.3 Tool Library is a library used for building IMS-certified LTI 1.3 tool providers in PHP. Prior to version 5.0, the function used to generate random nonces was not sufficiently cryptographically complex. Users should upgrade to version 5.0 to receive a patch. There are currently no known workarounds. |
Github GHSA |
GHSA-768m-5w34-2xf5 | LTI 1.3 Tool Library's function used to generate random nonces not sufficiently cryptographically complex before v5.0 |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Wed, 23 Apr 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-04-23T17:58:11.075Z
Reserved: 2022-05-18T00:00:00.000Z
Link: CVE-2022-31157
Updated: 2024-08-03T07:11:39.612Z
Status : Modified
Published: 2022-07-15T18:15:08.910
Modified: 2024-11-21T07:04:01.233
Link: CVE-2022-31157
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA