CGI::Session::ID::md5 versions before 4.49 for Perl generate predictable session ids from low-entropy sources. The gene
Amon2::Plugin::Web::CSRFDefender versions from 7.00 through 7.03 for Perl generate an insecure session id. The generate
Ado::Sessions versions through 0.935 for Perl generates insecure session ids. The session id is generated from a SHA-1
Amazon::Credentials versions through 1.2.0 for Perl uses rand to generate encryption keys. Amazon::Credentials stores c
Mojolicious::Sessions::Storable versions through 0.05 for Perl generate session ids insecurely. The default session id
GD::SecurityImage versions through 1.75 for Perl use rand to generate secrets. The random method creates the challenge
Values produced by ${random.value} are not suitable for use as secrets. ${random.uuid} is not affected. ${random.int} an
Crypt::ScryptKDF versions through 0.010 for Perl uses insecure random number source when no CSPRNG module is available.
UltraVNC through 1.8.2.2 uses a cryptographically weak pseudo-random number generator to produce VNC authentication chal
openssl_encrypt before 1.4.0 imports Python's non-cryptographic 'random' module (Mersenne Twister PRNG) at line 15 of op
Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Commun
The linqi application contains hardcoded cryptographic keys. Additionally, the application uses a weak algorithm with a
ExtremeXOS (EXOS) uses a challenge-response mechanism to authorize access to the privileged debug-mode function. The cha
Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) in the SonicOS SSLVPN authentication token generator
Delta Electronics COMMGR v1 and v2 uses insufficiently randomized values to generate session IDs (CWE-338). An attacker
In the OpenSSL compatibility layer implementation, the function RAND_poll() was not behaving as expected and leading to
Apache Druid’s Kerberos authenticator uses a weak fallback secret when the `druid.auth.authenticator.kerberos.cookieSign
Fiber Utils is a collection of common functions created for Fiber. In versions 2.0.0-rc.3 and below, when the system's c
FreshRSS is a free, self-hostable RSS aggregator. Prior to version 1.28.0, FreshRSS uses cryptographically weak random n
In jenkins/ssh-agent Docker images 6.11.1 and earlier, SSH host keys are generated on image creation for images based on
In jenkins/ssh-slave Docker images based on Debian, SSH host keys are generated on image creation for images based on De
Mojolicious::Plugin::CaptchaPNG version 1.05 for Perl uses a weak random number source for generating the captcha. That
Starch versions 0.14 and earlier generate session ids insecurely. The default session id generator returns a SHA-1 hash
Crypt::RandomEncryption for Perl version 0.01 uses insecure rand() function during encryption.
WBCE CMS is a content management system. Versions 1.6.4 and below use function GenerateRandomPassword() to create passwo
Crypt::Random Perl package 1.05 through 1.55 may use rand() function, which is not cryptographically strong, for cryptog
A vulnerability in langgenius/dify v0.10.1 allows an attacker to take over any account, including administrator accounts
Catalyst::Authentication::Credential::HTTP versions 1.018 and earlier for Perl generate nonces using the Perl Data::UUID
Data::Entropy for Perl 0.007 and earlier use the rand() function as the default source of entropy, which is not cryptogr
coturn is a free open source implementation of TURN and STUN Server. Versions 4.6.2r5 through 4.7.0-r4 have a bad random
A use of a cryptographically weak pseudo-random number generator vulnerability in the authenticator of the Identity Base
Apache::AuthAny::Cookie v0.201 or earlier for Perl generates session ids insecurely. Session ids are generated using an
A vulnerability was identified in the password generation algorithm when accessing the debug-interface. An unauthenticat
Plack-Middleware-Session before version 0.35 for Perl generates session ids insecurely. The default session id generato
Mojolicious::Plugin::CSRF 1.03 for Perl uses a weak random number source for generating CSRF tokens. That version of th
Net::Xero 0.044 and earlier for Perl uses the rand() function as the default source of entropy, which is not cryptograph
Authen::SASL::Perl::DIGEST_MD5 versions 2.04 through 2.1800 for Perl generates the cnonce insecurely. The cnonce (clien
Authen::DigestMD5 versions 0.01 through 0.02 for Perl generate the cnonce insecurely. The cnonce (client nonce) is gene
Catalyst::Plugin::Session before version 0.44 for Perl generates session ids insecurely. The session id is generated fr
Amon2::Auth::Site::LINE uses the String::Random module to generate nonce values. String::Random defaults to Perl's bui
Web::API 2.8 and earlier for Perl uses the rand() function as the default source of entropy, which is not cryptographica
Net::Dropbox::API 1.9 and earlier for Perl uses the rand() function as the default source of entropy, which is not crypt
WebService::Xero 0.11 and earlier for Perl uses the rand() function as the default source of entropy, which is not crypt
The Net::EasyTCP package before 0.15 for Perl always uses Perl's builtin rand(), which is not a strong random number gen
The Net::EasyTCP package 0.15 through 0.26 for Perl uses Perl's builtin rand() if no strong randomization module is pres
In Net::OAuth::Client in the Net::OAuth package before 0.29 for Perl, the default nonce is a 32-bit integer generated fr
Crypt::Salt for Perl version 0.01 uses insecure rand() function when generating salts for cryptographic purposes.
Mojolicious versions from 7.28 through 9.45 for Perl will generate weak HMAC session cookie secrets via "mojo generate a
DBIx::Class::EncodedColumn use the rand() function, which is not cryptographically secure to salt password hashes. This
DBIx::Class::EncodedColumn use the rand() function, which is not cryptographically secure to salt password hashes. This
Frequently Asked Questions
What is CWE-338?
CWE-338 (CWE-338) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-338?
There are 241 CVE records associated with CWE-338 in our database. Of these, 49 are critical severity, 77 are high severity, and 67 are medium severity.
How can I protect against CWE-338 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-338 using AI-powered security agents.
Detect CWE-338 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-338 vulnerabilities across your infrastructure.
Get Started