CVE-2015-7764

high
Published 2017-08-09 · Modified 2024-04-29
CVSS v3
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS v2
5.0
VIR risk
7.5

Description

Lemur 0.1.4 does not use sufficient entropy in its IV when encrypting AES in CBC mode.

Predictions

Exploit likelihood
83%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No vendor mitigations ingested yet for this CVE. The mitigation-content worker queues fetches as references arrive — check back in a few minutes, or see the references list below.

Package impact

EcosystemPackageVulnerableFixed
python PyPIlemur<0.1.50.1.5
python PyPIlemur<0.2.10.2.1

Application impact

VendorProductVersionsFixed
netflixlemur0.1.4

References

CWEs

CWE-331

Verify integrity in audit chain (admin only). AS-IS.