CVE-2021-29245: Weak RNG
Published May 5, 2021
·Updated
BTCPay Server through 1.0.7.0 uses a weak method Next to produce pseudo-random values to generate a legacy API key.
Affected Software
1 affected component
btcpayserver Btcpay Server<=1.0.7.0
Event History
May 5, 2021
CVE Published
via MITRE·12:25 PM
Data Sourced
via MITRE·12:25 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2021-29245?
CVE-2021-29245 has been assigned a medium severity level due to the potential exposure of legacy API keys.
2
How do I fix CVE-2021-29245?
To fix CVE-2021-29245, upgrade BTCPay Server to a version higher than 1.0.7.0.
3
What specific issue does CVE-2021-29245 address?
CVE-2021-29245 addresses the use of a weak random number generation method for creating legacy API keys.
4
Who is affected by CVE-2021-29245?
All users of BTCPay Server versions up to 1.0.7.0 are affected by CVE-2021-29245.
5
Are there any workarounds for CVE-2021-29245?
There are no effective workarounds for CVE-2021-29245 other than upgrading to a secure version.