#VU97753 Predictable Seed in Pseudo-Random Number Generator (PRNG) in aws - CVE-2024-41708
Published: September 27, 2024
aws
AdaCore
Description
The vulnerability allows a remote attacker to compromise the affected application.
The vulnerability exists due to usage of a weak random number generator within the Random_String() function in the src/core/aws-utils.adb module. A remote attacker can guess session identifiers of other users and gain unauthorized access to the application.