PT-2022-20572 · Unknown · Lti 1.3 Tool Library

·

CVE-2022-31157

·

Published

2022-07-15

·

Updated

2023-07-24

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions LTI 1.3 Tool Library versions prior to 5.0
Description The issue concerns the function used to generate random nonces, which was not sufficiently cryptographically complex. This could make values predictable and tokens forgable. There are no known workarounds.
Recommendations For versions prior to 5.0, upgrade to version 5.0 to receive a patch.

Exploit

Fix

Use of a Broken Cryptographic Algorithm

Use of Insufficiently Random Values

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-31157
GHSA-768M-5W34-2XF5

Affected Products

Lti 1.3 Tool Library