CVE-2021-3692: Use of Predictable Algorithm in Random Number Generator in yiisoft/yii2
Published Aug 10, 2021
·Updated
yii2 is vulnerable to Use of Predictable Algorithm in Random Number Generator
Affected Software
1 affected component
Yiiframework Yii>=2.0.0<2.0.43
Remediation
Event History
Aug 10, 2021
CVE Published
via MITRE·03:36 PM
Data Sourced
via MITRE·03:36 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2021-3692?
CVE-2021-3692 is a vulnerability in yii2 that allows an attacker to predict the random number generator algorithm.
2
What is the severity of CVE-2021-3692?
The severity of CVE-2021-3692 is high with a severity value of 5.3.
3
How does CVE-2021-3692 affect yii2?
CVE-2021-3692 affects yii2 versions from 2.0.0 to 2.0.43.
4
How can I fix CVE-2021-3692 in yii2?
To fix CVE-2021-3692 in yii2, you should update to a version that includes the fix, such as the commit 13f27e4d920a05d53236139e8b07007acd046a46 on the yii2 GitHub repository.
5
Are there any references for CVE-2021-3692?
Yes, you can find references for CVE-2021-3692 on the following links: [GitHub Commit](https://github.com/yiisoft/yii2/commit/13f27e4d920a05d53236139e8b07007acd046a46) and [Huntr Bounty](https://huntr.dev/bounties/55517f19-5c28-4db2-8b00-f78f841e8aba).