HomeDefault status
unaffected
Any version before 0.1.1
affected
Description
Authen::TOTP versions before 0.1.1 for Perl generate secrets using rand. Secrets were generated using Perl's built-in rand function, which is predictable and unsuitable for security usage.
Problem types
Product status
Any version before 0.1.1
References
metacpan.org/release/TCHATZI/Authen-TOTP-0.1.1/changes
github.com/...d04f30cc6538d77fc6b6d550da450cf3017b8561.patch