CVE-2025-22376

Publication date

2025-01-03 00:00:00

Family

mitre

State

PUBLISHED

Description

In Net::OAuth::Client in the Net::OAuth package before 0.29 for Perl, the default nonce is a 32-bit integer generated from the built-in rand() function, which is not cryptographically strong.