CVE-2013-4347

Severity CVSS v4.0:
Pending analysis
Type:
CWE-310 Cryptographic Issues
Publication date:
20/05/2014
Last modified:
12/04/2025

Description

The (1) make_nonce, (2) generate_nonce, and (3) generate_verifier functions in SimpleGeo python-oauth2 uses weak random numbers to generate nonces, which makes it easier for remote attackers to guess the nonce via a brute force attack.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:urbanairship:python-oauth2:-:*:*:*:*:*:*:*