HIGH 7.5 PyPI

Plone and Zope2 do not reseed pseudo-random number generator

GHSA-48vv-2pmq-9fvv · CVE-2012-6661 · PYSEC-2014-51 · PYSEC-2014-76

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

Zope before 2.13.19, as used in Plone before 4.2.3 and 4.3 before beta 1, does not reseed the pseudo-random number generator (PRNG), which makes it easier for remote attackers to guess the value via unspecified vectors. NOTE: this issue was SPLIT from CVE-2012-5508 due to different vulnerability types (ADT2).

Ready to move

Start Securing

Free, no credit card | First findings in minutes