Duplicate Advisory: Lemur subject to insecure random generation
High severity
GitHub Reviewed
Published
Apr 19, 2023
to the GitHub Advisory Database
•
Updated Sep 30, 2024
Withdrawn
This advisory was withdrawn on Sep 30, 2024
Description
Published by the National Vulnerability Database
Apr 19, 2023
Published to the GitHub Advisory Database
Apr 19, 2023
Reviewed
Sep 30, 2024
Withdrawn
Sep 30, 2024
Last updated
Sep 30, 2024
Duplicate Advisory
This advisory has been withdrawn because it is a duplicate of GHSA-5fqv-mpj8-h7gm. This link is maintained to preserve external references.
Original Description
Netflix Lemur before version 1.3.2 used insufficiently random values when generating default credentials. The insufficiently random values may allow an attacker to guess the credentials and gain access to resources managed by Lemur.
References