PT-2022-20572 · Unknown · Lti 1.3 Tool Library

Dbhynds

·

Published

2022-07-15

·

Updated

2023-07-24

·

CVE-2022-31157

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions LTI 1.3 Tool Library versions prior to 5.0
Description The issue concerns the function used to generate random nonces, which was not sufficiently cryptographically complex. This could make values predictable and tokens forgable. There are no known workarounds.
Recommendations For versions prior to 5.0, upgrade to version 5.0 to receive a patch.

Exploit

Fix

Use of a Broken Cryptographic Algorithm

Use of Insufficiently Random Values

Weakness Enumeration

Related Identifiers

CVE-2022-31157
GHSA-768M-5W34-2XF5

Affected Products

Lti 1.3 Tool Library