{"id":"GHSA-q8fc-v85f-78pw","aliases":[],"url":"https://o3.security/vulnerability/GHSA-q8fc-v85f-78pw","summary":"stormpath/sdk uses Insecure Random Number Generator","details":"The vulnerability pertains to the usage of an insecure random number generator (RNG) in the \"stormpath-sdk-php\" library. Specifically, the issue is present in the generation of UUID (Universally Unique Identifier) version 4 within the codebase.\n","published":"2024-05-29T13:09:29Z","modified":"2024-12-04T05:40:09.638665Z","cvss":{"score":5.3,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"stormpath/sdk","fixedVersion":null}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/stormpath/stormpath-sdk-php/issues/132"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/stormpath/sdk/2017-11-20.yaml"},{"type":"PACKAGE","url":"https://github.com/stormpath/stormpath-sdk-php"},{"type":"WEB","url":"https://github.com/stormpath/stormpath-sdk-php/blob/15aee3007b8aa41c20cdf28fd650b8a2368a7fa9/src/Util/UUID.php#L167-L181"},{"type":"WEB","url":"https://github.com/stormpath/stormpath-sdk-php/blob/62698ea98ef89217f932e28cf3e511d39af3b4cf/src/Authc/Api/ApiKeyEncryptionOptions.php#L48-L50"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-12-04T05:40:09.638665Z"}}