Python Oauth2
Vendor:
First CVE: May 20, 2014 · Active for 12 years
2
Total CVEs
More Total CVEs than 49% of tracked products
2.0
Avg CVEs / Year
Higher CVE frequency than 60% of tracked products
5.0
Avg CVSS
Higher Avg CVSS than 9% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Python Oauth2 over time
Volume of CVEsAvg CVSS Base Score
First CVE
May 20, 2014
12 years ago
Most Recent CVE
May 20, 2014
4,448 days ago
CVE Severity & Scoring
Python Oauth22 CVEs
100%
All CVEs352,294 CVEs
45%
40%
11%
Medium
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown2 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown2 (100.0%)
User Interaction
None0 (0.0%)
Unknown2 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown2 (100.0%)
Top CVEs
Signals from CVEs in this product scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2013-4347MEDIUM The (1) make_nonce, (2) generate_nonce, and (3) generate_verifier functions in SimpleGeo python-oauth2 uses weak random numbers to generate nonces, which makes it easier for remote | May 20, 2014 | 5.8 | 17 | NO | NO |
CVE-2013-4346MEDIUM The Server.verify_request function in SimpleGeo python-oauth2 does not check the nonce, which allows remote attackers to perform replay attacks via a signed URL. | May 20, 2014 | 4.3 | 14 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (2 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (2 CVEs).
Media Mentions
Signals from CVEs in this product scope (2 CVEs).
Top CNAs Publishing CVEs For Python Oauth2
Versions
No cataloged versions.