CVE-2025-27552

CVSS 3.1 Score 4 of 10 (medium)

Details

Published Mar 26, 2025
Updated: Mar 27, 2025
CWE ID 338

Summary

CVE-2025-27552 is a vulnerability affecting DBIx::Class::EncodedColumn, a module used for encoding columns in DBIx::Class. The issue lies in the use of the rand() function, which is not cryptographically secure, for salting password hashes. This weakness can potentially allow an attacker to decipher password hashes, posing a significant security risk. The affected version of DBIx::Class::EncodedColumn is up to and including 0.00032. The vulnerability is specifically related to the Crypt/Eksblowfish/Bcrypt.pm program file.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share