Loading HuntDB...

GHSA-ggfx-h9xj-5v9c

GitHub Security Advisory

Insecure PRNG use in random_password_generator

✓ GitHub Reviewed HIGH Has CVE

Advisory Details

The random_password_generator (aka RandomPasswordGenerator) gem through 1.0.0 for Ruby uses Kernel#rand to generate passwords, which, due to its cyclic nature, can facilitate password prediction.

Affected Packages

RubyGems random_password_generator
Affected versions: 0 (last affected: 1.0.0)

Related CVEs

Key Information

GHSA ID
GHSA-ggfx-h9xj-5v9c
Published
May 19, 2022 12:00 AM
Last Modified
May 31, 2022 11:27 PM
CVSS Score
7.5 /10
Primary Ecosystem
RubyGems
Primary Package
random_password_generator
GitHub Reviewed
✓ Yes

Dataset

Last updated: July 1, 2025 6:26 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.