DirectorySecurity Advisories
Sign In
Security Advisories

CGA-x9jv-q6hx-gq7c

Published

Last updated

https://images.chainguard.dev/security/CGA-x9jv-q6hx-gq7c
Package

dynamic-localpv-provisioner-fips

Latest Update
Fixed
Fixed Version

3.5.0-r0

Aliases
  • CVE-2021-4238
  • GHSA-3839-6r69-m497

Severity

9.1

Critical

CVSS V3

Summary

GoUtils's randomly-generated alphanumeric strings contain significantly less entropy than expected

Description

Randomly-generated alphanumeric strings contain significantly less entropy than expected. The RandomAlphaNumeric and CryptoRandomAlphaNumeric functions always return strings containing at least one digit from 0 to 9. This significantly reduces the amount of entropy in short strings generated by these functions.

References

Updates


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2024 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard Images