PT-2025-12875 · Unknown+2 · Dbix::Class::Encodedcolumn+2
Robert Rothenberg
·
Published
2025-03-26
·
Updated
2026-02-09
·
CVE-2025-27551
CVSS v3.1
4.0
Medium
| Vector | AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
DBIx::Class::EncodedColumn versions prior to 0.00032
Description
The issue arises from the use of the
rand() function, which is not cryptographically secure, to salt password hashes. This is associated with the program file lib/DBIx/Class/EncodedColumn/Digest.pm.Recommendations
For versions prior to 0.00032, update to version 0.00032 or later to resolve the issue. As a temporary workaround, consider disabling the use of
rand() for salting password hashes until a patch is available. Restrict access to password hashing functions to minimize the risk of exploitation. Avoid using the rand() function in sensitive cryptographic operations until the issue is resolved.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Dbix::Class::Encodedcolumn
Debian
Red Os