Vulnerability Description
A flaw was found in github.com/satori/go.uuid in versions from commit 0ef6afb2f6cdd6cdaeee3885a95099c63f18fc8c to d91630c8510268e75203009fe7daf2b8e1d60c45. Due to insecure randomness in the g.rand.Read function the generated UUIDs are predictable for an attacker.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Satori | Uuid | - |
Related Weaknesses (CWE)
References
- https://bugzilla.redhat.com/show_bug.cgi?id=1954376Issue TrackingThird Party Advisory
- https://github.com/satori/go.uuid/issues/73Third Party Advisory
- https://snyk.io/vuln/SNYK-GOLANG-GITHUBCOMSATORIGOUUID-72488Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1954376Issue TrackingThird Party Advisory
- https://github.com/satori/go.uuid/issues/73Third Party Advisory
- https://snyk.io/vuln/SNYK-GOLANG-GITHUBCOMSATORIGOUUID-72488Third Party Advisory
FAQ
What is CVE-2021-3538?
CVE-2021-3538 is a vulnerability with a CVSS score of 9.8 (CRITICAL). A flaw was found in github.com/satori/go.uuid in versions from commit 0ef6afb2f6cdd6cdaeee3885a95099c63f18fc8c to d91630c8510268e75203009fe7daf2b8e1d60c45. Due to insecure randomness in the g.rand.Rea...
How severe is CVE-2021-3538?
CVE-2021-3538 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2021-3538?
Check the references section above for vendor advisories and patch information. Affected products include: Satori Uuid.