PYSEC-2024-5

See a problem?
Import Source
https://github.com/pypa/advisory-database/blob/main/vulns/case-utils/PYSEC-2024-5.yaml
JSON Data
https://api.test.osv.dev/v1/vulns/PYSEC-2024-5
Aliases
Published
2024-01-11T03:15:00Z
Modified
2025-09-19T04:24:00.177173Z
Severity
  • 2.8 (Low) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N CVSS Calculator
Summary
[none]
Details

cdo-local-uuid project provides a specialized UUID-generating function that can, on user request, cause a program to generate deterministic UUIDs. An information leakage vulnerability is present in cdo-local-uuid at version 0.4.0, and in case-utils in unpatched versions (matching the pattern 0.x.0) at and since 0.5.0, before 0.15.0. The vulnerability stems from a Python function, cdo_local_uuid.local_uuid(), and its original implementation case_utils.local_uuid().

References

Affected packages

PyPI / case-utils

Package

Affected ranges

Type
GIT
Repo
https://github.com/Cyber-Domain-Ontology/CDO-Utility-Local-UUID
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Type
GIT
Repo
https://github.com/casework/CASE-Utilities-Python
Events
Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

0.*
0.5.0
0.5.1
0.5.1.post0
0.6.0
0.6.1
0.7.0
0.7.1
0.8.0
0.8.1
0.8.1.post0
0.9.0
0.9.1
0.9.1.post0
0.10.0
0.10.1
0.10.1.post0
0.11.0
0.11.1
0.11.1.post0
0.12.0
0.12.1
0.12.1.post0
0.13.0
0.13.1
0.13.1.post0
0.14.0
0.14.1
0.14.1.post0
0.15.0
0.16.0
0.17.0

Database specific

source
"https://github.com/pypa/advisory-database/blob/main/vulns/case-utils/PYSEC-2024-5.yaml"