PT-2025-21862 · Unknown · Calmkart Django-Sso-Server

Dev03303

·

Published

2025-05-18

·

Updated

2025-05-18

·

CVE-2025-4894

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: calmkart Django-sso-server up to 057247929a94ffc358788a37ab99e391379a4d15
Description: A vulnerability was found in the function gen rsa keys of the file common/crypto.py, leading to inadequate encryption strength. The attack can be initiated remotely, but the complexity of an attack is rather high, and the exploitation appears to be difficult.
Recommendations: As a temporary workaround, consider disabling the gen rsa keys function until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Inadequate Encryption Strength

Weakness Enumeration

Related Identifiers

CVE-2025-4894

Affected Products

Calmkart Django-Sso-Server