GHSA-ggfx-h9xj-5v9c
GitHub Security Advisory
Insecure PRNG use in random_password_generator
✓ GitHub Reviewed
HIGH
Has CVE
Advisory Details
The random_password_generator (aka RandomPasswordGenerator) gem through 1.0.0 for Ruby uses Kernel#rand to generate passwords, which, due to its cyclic nature, can facilitate password prediction.
Affected Packages
RubyGems
random_password_generator
Affected versions:
0
(last affected: 1.0.0)
Related CVEs
Key Information
7.5
/10
Dataset
Last updated: July 1, 2025 6:26 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.