Filtered by vendor Urbanairship Subscriptions
Filtered by product Python-oauth2 Subscriptions
Total 2 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2013-4347 1 Urbanairship 1 Python-oauth2 2023-02-13 N/A
The (1) make_nonce, (2) generate_nonce, and (3) generate_verifier functions in SimpleGeo python-oauth2 uses weak random numbers to generate nonces, which makes it easier for remote attackers to guess the nonce via a brute force attack.
CVE-2013-4346 1 Urbanairship 1 Python-oauth2 2023-02-13 N/A
The Server.verify_request function in SimpleGeo python-oauth2 does not check the nonce, which allows remote attackers to perform replay attacks via a signed URL.