CVE-2024-52322
CVSS 3.1 Score 5.5 of 10 (medium)
Details
Summary
CVE-2024-52322: Perl's WebService::Xero 0.11 and earlier versions utilize the insecure rand() function as the default source of entropy for cryptographic operations. This vulnerability arises due to the use of the Data::Random library, which is primarily intended for testing purposes and relies on the rand() function for generating random numbers. This weakness in the entropy source could lead to predictable cryptographic keys, potentially enabling unauthorized access or data manipulation. Users are advised to upgrade to a secure and cryptographically robust entropy source in their WebService::Xero implementation.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.