CVE-2021-4238

Severity CVSS v4.0:
Pending analysis
Type:
CWE-331 Insufficient Entropy
Publication date:
27/12/2022
Last modified:
11/04/2025

Description

Randomly-generated alphanumeric strings contain significantly less entropy than expected. The RandomAlphaNumeric and CryptoRandomAlphaNumeric functions always return strings containing at least one digit from 0 to 9. This significantly reduces the amount of entropy in short strings generated by these functions.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:goutils_project:goutils:*:*:*:*:*:go:*:* 1.1.1 (excluding)