Vulnerabilities
Vulnerable Software
Urbanairship:  >> Python-Oauth2  Security Vulnerabilities
The Server.verify_request function in SimpleGeo python-oauth2 does not check the nonce, which allows remote attackers to perform replay attacks via a signed URL.
CVSS Score
4.3
EPSS Score
0.001
Published
2014-05-20
The (1) make_nonce, (2) generate_nonce, and (3) generate_verifier functions in SimpleGeo python-oauth2 uses weak random numbers to generate nonces, which makes it easier for remote attackers to guess the nonce via a brute force attack.
CVSS Score
5.8
EPSS Score
0.001
Published
2014-05-20


Contact Us

Shodan ® - All rights reserved