HIGH7.5
PYSEC-2023-245
Details
PyPinkSign v0.5.1 uses a non-random or static IV for Cipher Block Chaining (CBC) mode in AES encryption. This vulnerability can lead to the disclosure of information and communications.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/pypinksign
Introduced in:
0No fixed version published yet for pypinksign (pip). Pin to a known-safe version or switch to an alternative.