CVE-2025-22376

Description

A flaw was found in perl-Net-OAuth. This vulnerability allows predictable nonce generation via insufficient cryptographic strength.

Statement

This vulnerability doesn't affect any supported Red Hat product.

Understanding the Weakness (CWE)

Access Control

Technical Impact: Bypass Protection Mechanism

If a PRNG is used for authentication and authorization, such as a session ID or a seed for generating a cryptographic key, then an attacker may be able to easily guess the ID or cryptographic key and gain access to restricted functionality.

Frequently Asked Questions

Want to get errata notifications? Sign up here.