A vulnerability classified as problematic was found in calmkart Django-sso-server up to 057247929a94ffc358788a37ab99e391379a4d15. This vulnerability affects the function gen_rsa_keys of the file common/crypto.py. The manipulation leads to inadequate encryption strength. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available.
History

Thu, 05 Jun 2025 20:00:00 +0000

Type Values Removed Values Added
First Time appeared Calmkart
Calmkart django-sso-server
CPEs cpe:2.3:a:calmkart:django-sso-server:*:*:*:*:*:*:*:*
Vendors & Products Calmkart
Calmkart django-sso-server

Mon, 19 May 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 18 May 2025 20:15:00 +0000

Type Values Removed Values Added
Description A vulnerability classified as problematic was found in calmkart Django-sso-server up to 057247929a94ffc358788a37ab99e391379a4d15. This vulnerability affects the function gen_rsa_keys of the file common/crypto.py. The manipulation leads to inadequate encryption strength. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available.
Title calmkart Django-sso-server crypto.py gen_rsa_keys inadequate encryption
Weaknesses CWE-310
CWE-326
References
Metrics cvssV2_0

{'score': 2.6, 'vector': 'AV:N/AC:H/Au:N/C:P/I:N/A:N'}

cvssV3_0

{'score': 3.7, 'vector': 'CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N'}

cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 6.3, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published: 2025-05-18T20:00:09.114Z

Updated: 2025-05-19T14:09:15.093Z

Reserved: 2025-05-17T09:55:32.398Z

Link: CVE-2025-4894

cve-icon Vulnrichment

Updated: 2025-05-19T14:09:11.813Z

cve-icon NVD

Status : Analyzed

Published: 2025-05-18T20:15:18.803

Modified: 2025-06-05T19:39:01.520

Link: CVE-2025-4894

cve-icon Redhat

No data.