This repository has been archived by the owner on May 22, 2024. It is now read-only.
github.com/satori/go.uuid-v1.2.0: 1 vulnerabilities (highest severity is: 9.8) - autoclosed #66
Labels
Mend: dependency security vulnerability
Security vulnerability detected by WhiteSource
Vulnerable Library - github.com/satori/go.uuid-v1.2.0
UUID package for Go
Vulnerabilities
Details
CVE-2021-3538
Vulnerable Library - github.com/satori/go.uuid-v1.2.0
UUID package for Go
Dependency Hierarchy:
Found in base branch: improbable
Vulnerability Details
A flaw was found in github.com/satori/go.uuid in versions from commit 0ef6afb2f6cdd6cdaeee3885a95099c63f18fc8c to d91630c8510268e75203009fe7daf2b8e1d60c45. Due to insecure randomness in the g.rand.Read function the generated UUIDs are predictable for an attacker.
Publish Date: 2021-06-02
URL: CVE-2021-3538
CVSS 3 Score Details (9.8)
Base Score Metrics:
Suggested Fix
Type: Upgrade version
Origin: satori/go.uuid#75
Release Date: 2021-06-02
Fix Resolution: github.com/satori/go.uuid - 75cca531ea763666bc46e531da3b4c3b95f64557
The text was updated successfully, but these errors were encountered: