HIGH 7.5 PyPI
Lemur uses static IV per key
GHSA-chg9-3c3p-ch23 · CVE-2015-7764 · PYSEC-2017-50
Published · Modified
Description
Lemur 0.1.4 does not use sufficient entropy in its IV when encrypting AES in CBC mode.
References
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2015-7764
- WEB https://github.com/Netflix/lemur/issues/117
- WEB https://github.com/kvesteri/sqlalchemy-utils/issues/166
- WEB https://github.com/Netflix/lemur/commit/394e18f76e5eb534d95160945ebc231ec3b4c794
- PACKAGE https://github.com/Netflix/lemur
- WEB https://github.com/pypa/advisory-database/tree/main/vulns/lemur/PYSEC-2017-50.yaml
- WEB http://www.openwall.com/lists/oss-security/2015/10/20/3
Ready to move
Start Securing
Free, no credit card | First findings in minutes