Maypole versions from 2.10 through 2.13 for Perl generates session ids insecurely. The session id is seeded with the sys
Concierge::Sessions versions from 0.8.1 before 0.8.5 for Perl generate insecure session ids. The generate_session_id fun
Plack::Middleware::Session::Simple versions before 0.05 for Perl generates session ids insecurely. The default session
Amon2 versions before 6.17 for Perl use an insecure random_string implementation for security functions. In versions 6.
HTTP::Session versions before 0.54 for Perl defaults to using insecurely generated session ids. HTTP::Session defaults
In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 account
Rejetto HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the non-cryptographic Math.random() generato
Crypt::Password versions through 0.28 for Perl generate insecure random values for salts. These versions use the built-
Fiber is an Express inspired web framework written in Go. Before 2.52.11, on Go versions prior to 1.24, the underlying c
WireGuard Easy through 15.3.0, fixed in commit 66b292b, contains a cryptographically weak one-time link token generation
Smolder versions through 1.51 for Perl uses insecure rand() function for cryptographic functions. Smolder 1.51 and earl
Apache::Session::Generate::MD5 versions through 1.94 for Perl create insecure session id. Apache::Session::Generate::MD
Net::NSCA::Client versions through 0.009002 for Perl uses a poor random number generator. Version v0.003 switched to us
Versions of the package jsrsasign from 7.0.0 and before 11.1.1 are vulnerable to Incomplete Comparison with Missing Fact
Business::OnlinePayment::StoredTransaction versions through 0.01 for Perl uses an insecure secret key. Business::Online
Solstice::Session versions through 1440 for Perl generates session ids insecurely. The _generateSessionID method return
Crypt::SaltedHash versions through 0.09 for Perl generate insecure random values for salts. These versions use the buil
Dancer2::Plugin::Auth::OAuth versions before 0.22 for Perl default to a predictable nonce. The default nonce was genera
Mojolicious::Plugin::Web::Auth::OAuth2 versions through 0.17 for Perl have an insecure default state parameter. When no
IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow disclosure of all stored credentials due to the use of a weak
Joomla Extension - regularlabs.com - Insecure login URL keys in IP login extension - Persistent URL login keys were also
sm-crypto provides JavaScript implementations of the Chinese cryptographic algorithms SM2, SM3, and SM4. Prior to 0.5.0,
crypto-js is a JavaScript library of crypto standards. Versions of crypto-js prior to 4.0.0 generate randomness in Crypt
The DoLogin Security plugin for WordPress is vulnerable to Authentication Bypass via Insufficient Randomness in all vers
RELATE is a web-based courseware package. Prior to commit 2f68e16, RELATE is vulnerable to predictable token generation
When enabling Spring Boot DevTools support for a remote application target (for example a Docker container or Cloud Foun
Apache::SessionX versions through 2.01 for Perl create insecure session id. Apache::SessionX generates session ids inse
Dancer2 versions through 2.1.0 for Perl generate insecure session ids when required CSPRNG modules are unavailable. Dan
Cloudreve is a self-hosted file management and sharing system. Prior to version 4.13.0, the application uses the weak ps
The urwid web display backend (urwid/display/web.py) generates web session identifiers (urwid_id) in Screen.start() by c
PAGI::Middleware::Session::Store::Cookie versions through 0.001003 for Perl generates random bytes insecurely. PAGI::Mi
Apache::API::Password versions through 0.5.2 for Perl can generate insecure random values for salts. The _make_salt and
CryptX versions before 0.088 for Perl do not reseed the Crypt::PK PRNG state after forking. The Crypt::PK::RSA, Crypt::
Crypt::PasswdMD5 versions through 1.42 for Perl generates insecure random values for salts. The built-in rand function
Weak Randomness / Insecure Cryptographic Primitive (CWE-338) in Get-RandomPassword in BOSH-Ecosystem / windows-utilities
HAX CMS helps manage microsite universe with PHP or NodeJs backends. Versions prior to 26.0.1 use `uniqid` for generatin
Crypt::PBKDF2 versions before 0.261630 for Perl generate insecure random values for salts. These versions use the built
A flaw was found in the Data Science Pipelines Operator. This vulnerability allows an unauthenticated attacker to derive
openssl_encrypt versions before 1.4.0 use Python's non-cryptographic random module for steganographic pixel selection in
UltraVNC through 1.8.2.2 uses inadequate cryptography in the MS-Logon II authentication scheme (rfbUltraVNC_MsLogonIIAut
IBM Langflow OSS contains a weak cryptographic key derivation vulnerability in the ensure_fernet_key() function.
WWW::OAuth 1.000 and earlier for Perl uses the rand() function as the default source of entropy, which is not cryptograp
A flaw was found in librest. The PKCE implementation for OAuth authorization uses the GRand function from the GLib API,
An issue was discovered in Mbed TLS before 3.6.6 and 4.x before 4.1.0 and TF-PSA-Crypto before 1.1.0. There is a Predict
HTTP::Session2 versions before 1.12 for Perl for Perl may generate weak session ids using the rand() function. The HTTP
WebDyne::Session versions before 3.003_704 for Perl generate the session id insecurely. The session handler generates t
Apache::Session::Generate::SHA256 versions before 1.3.19 for Perl create insecure session ids. Apache::Session::Generat
SmarterTools SmarterMail builds prior to 9610 contain a cryptographic weakness in the file and email sharing endpoints t
Dancer::Session::Abstract versions through 1.3522 for Perl generates session ids insecurely. The session id is generate
Net::BitTorrent versions before 2.1.0 for Perl generate the MSE Diffie-Hellman private key with a non-cryptographic PRNG
Frequently Asked Questions
What is CWE-338?
CWE-338 (CWE-338) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-338?
There are 63 CVE records associated with CWE-338 in our database. Of these, 23 are critical severity, 19 are high severity, and 17 are medium severity.
How can I protect against CWE-338 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-338 using AI-powered security agents.
Detect CWE-338 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-338 vulnerabilities across your infrastructure.
Get Started