Back

HIGH

(Plone): Python random generator used instead of system random generator

Published Nov 3, 2014

Description

Zope before 2.13.19, as used in Plone before 4.2.3 and 4.3 before beta 1, does not reseed the pseudo-random number generator (PRNG), which makes it easier for remote attackers to guess the value via unspecified vectors. NOTE: this issue was SPLIT from CVE-2012-5508 due to different vulnerability types (ADT2).

Affected products

Remediation

Red Hat statement

Not vulnerable. This issue did not affect the versions of luci (as provided by conga) as shipped with Red Hat Enterprise Linux 5.

Metrics

References (12)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Nov 3, 2014
Updated Sep 16, 2024
Reserved Nov 3, 2014
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Low
Public date Nov 6, 2012
GHSA-48VV-2PMQ-9FVV