WP OAuth Server (OAuth Authentication) < 3.1.5 - Pseudorandom Number Generation

2015-08-12 00:00
Mallory Adams

Strategic Overview

Status
Patched in 3.1.5
Affected Version< 3.1.5
CVSS9.8Critical
CVECVE-2015-9435
View all WP OAuth Server (OAuth Authentication) vulnerabilities

Vulnerability Overview

The oauth2-provider plugin before 3.1.5 for WordPress has incorrect generation of random numbers.

Technical Analysis

REMEDIATION: Update to version 3.1.5, or a newer patched version --- IDENTIFIER: CWE-338 (Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)) The product uses a Pseudo-Random Number Generator (PRNG) in a security context, but the PRNG's algorithm is not cryptographically strong.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C