VDB
Sign up
HIGH7.5

PYSEC-2023-245

Details

PyPinkSign v0.5.1 uses a non-random or static IV for Cipher Block Chaining (CBC) mode in AES encryption. This vulnerability can lead to the disclosure of information and communications.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/pypinksign
Introduced in: 0

No fixed version published yet for pypinksign (pip). Pin to a known-safe version or switch to an alternative.

References