Skip to content

Critical confidentiality flaw

Critical
ArjunSharda published GHSA-mhhf-vgwh-fw9h Dec 6, 2022

Package

pip Passeo (pip)

Affected versions

< 1.0.5

Patched versions

1.0.5

Description

Impact

Everyone below v1.0.5 is impacted by this flaw, of confidentiality being at risk due to the password(s) being easily able to be guessed with Passeo's use of the random library. It is recommended to change any passwords made with Passeo before v1.0.5 and upgrade to v1.0.5, and v1.0.5 patches this with the secrets library.

Workarounds

No current workaround available than updating to v1.0.5.

Severity

Critical

CVE ID

CVE-2022-23472

Weaknesses

No CWEs

Credits