{"id":"CVE-2021-3692","aliases":["GHSA-wwvv-x5mq-h3jj"],"url":"https://o3.security/vulnerability/CVE-2021-3692","summary":"Use of Cryptographically Weak Pseudo-Random Number Generator in yiisoft/yii2-dev","details":"yii2 is vulnerable to Use of Predictable Algorithm in Random Number Generator","published":"2021-08-10T17:15:10.900Z","modified":"2026-08-07T17:02:25.740060Z","cvss":{"score":5.3,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"Packagist","name":"yiisoft/yii2-dev","fixedVersion":"2.0.43"}],"fix":{"url":"https://github.com/yiisoft/yii2/commit/13f27e4d920a05d53236139e8b07007acd046a46","label":"yiisoft/yii2@13f27e4"},"references":[{"type":"REPORT","url":"https://huntr.dev/bounties/55517f19-5c28-4db2-8b00-f78f841e8aba"},{"type":"FIX","url":"https://github.com/yiisoft/yii2/commit/13f27e4d920a05d53236139e8b07007acd046a46"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T17:02:25.740060Z"}}