{"id":"CVE-2019-25061","details":"The random_password_generator (aka RandomPasswordGenerator) gem through 1.0.0 for Ruby uses Kernel#rand to generate passwords, which, due to its cyclic nature, can facilitate password prediction.","aliases":["GHSA-ggfx-h9xj-5v9c"],"modified":"2026-07-08T16:27:56.008839Z","published":"2022-05-18T11:15:10.670Z","references":[{"type":"ADVISORY","url":"https://github.com/bvsatyaram/random_password_generator/blob/2855e8d7d8803dbb580ddd6cf13846394eb4530e/lib/random_password_generator.rb#L23"},{"type":"ADVISORY","url":"https://ruby-doc.org/core-3.1.2/Random.html"},{"type":"REPORT","url":"https://github.com/bvsatyaram/random_password_generator/pull/1"},{"type":"EVIDENCE","url":"https://stackoverflow.com/questions/42170239/security-of-rand-in-ruby-compared-to-other-methods/42170560"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/bvsatyaram/random_password_generator","events":[{"introduced":"0"},{"last_affected":"6d972b6095d93a847d96ee5f4b9b50e0583dc627"}],"database_specific":{"cpe":"cpe:2.3:a:random_password_generator_project:random_password_generator:*:*:*:*:*:ruby:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"1.0.0"}],"source":"CPE_RANGE"}}],"versions":["v1.0.0","v0.0.5","v0.0.4","v0.0.3","v0.0.2","v0.0.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-25061.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}