HomeDefault status
unaffected
Any version
affected
Description
Crypt::SaltedHash versions through 0.09 for Perl generate insecure random values for salts. These versions use the built-in rand function, which is predictable and unsuitable for cryptography.
Problem types
CWE-338 Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)
Product status
Any version
References
metacpan.org/release/RRWO/Crypt-SaltedHash-0.10/changes
github.com/...9b68437d2cd420b819b3a795474c3870338d38d5.patch