漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Amazon::Credentials versions through 1.2.0 for Perl uses rand to generate encryption keys
Vulnerability Description
Amazon::Credentials versions through 1.2.0 for Perl uses rand to generate encryption keys. Amazon::Credentials stores credentials in an obfuscated form to prevent access to the secrets from a data dump of the object. Before version 1.3.0, the secrets were encrypted using a 64-bit key that was generated using the built-in rand function, which is predictable and unsuitable for cryptography.
CVSS Information
N/A
Vulnerability Type
使用具有密码学弱点缺陷的PRNG
Vulnerability Title
Amazon::Credentials 安全特征问题漏洞
Vulnerability Description
Amazon::Credentials是BIGFOOT个人开发者的一个用于管理云服务访问密钥与认证信息的凭证处理库。 Amazon::Credentials 1.2.0及之前版本存在安全特征问题漏洞,该漏洞源于使用rand函数生成加密密钥,Amazon::Credentials以混淆形式存储凭据,1.3.0之前版本使用内置rand函数生成的64位密钥加密秘密,该函数可预测且不适合加密用途。
CVSS Information
N/A
Vulnerability Type
N/A