Description
Data::Entropy for Perl 0.007 and earlier use the rand() function as the default source of entropy, which is not cryptographically secure, for cryptographic functions.
References (3)
Core 3
Core References
Various Sources
https://perldoc.perl.org/functions/rand
Scores
CVSS v3
7.7
EPSS
0.0016
EPSS Percentile
5.2%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-331
CWE-338
Status
published
Products (1)
ZEFRAM/Data::Entropy
< 0.008
Published
Mar 28, 2025
Tracked Since
Feb 18, 2026