Netflix Lemur before version 1.3.2 used insufficiently random values when generating default credentials. The insufficiently random values may allow an attacker to guess the credentials and gain access to resources managed by Lemur.
History

Wed, 05 Feb 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2025-02-05T14:50:36.951Z

Reserved: 2023-04-18T10:31:45.962Z

Link: CVE-2023-30797

cve-icon Vulnrichment

Updated: 2024-08-02T14:37:15.447Z

cve-icon NVD

Status : Modified

Published: 2023-04-19T20:15:12.377

Modified: 2025-02-05T15:15:19.940

Link: CVE-2023-30797

cve-icon Redhat

No data.