Files
CVEs-PoC/2021/CVE-2021-3538.md
T
2025-09-29 21:09:30 +02:00

18 lines
901 B
Markdown

### [CVE-2021-3538](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3538)
![](https://img.shields.io/static/v1?label=Product&message=satori%2Fgo.uuid&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=All%20satori%2Fgo.uuid%20versions%20from%20commit%200ef6afb2f6cdd6cdaeee3885a95099c63f18fc8c%20to%20d91630c8510268e75203009fe7daf2b8e1d60c45%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-338&color=brightgreen)
### Description
A flaw was found in github.com/satori/go.uuid in versions from commit 0ef6afb2f6cdd6cdaeee3885a95099c63f18fc8c to d91630c8510268e75203009fe7daf2b8e1d60c45. Due to insecure randomness in the g.rand.Read function the generated UUIDs are predictable for an attacker.
### POC
#### Reference
- https://github.com/satori/go.uuid/issues/73
#### Github
- https://github.com/fkie-cad/nvd-json-data-feeds