CVE-2025-4894

A vulnerability classified as problematic was found in calmkart Django-sso-server up to 057247929a94ffc358788a37ab99e391379a4d15. This vulnerability affects the function gen_rsa_keys of the file common/crypto.py. The manipulation leads to inadequate encryption strength. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available.
References
Link Resource
https://vuldb.com/?ctiid.309448 Permissions Required VDB Entry
https://vuldb.com/?id.309448 Third Party Advisory VDB Entry
https://vuldb.com/?submit.578019 Third Party Advisory VDB Entry Exploit
Configurations

Configuration 1 (hide)

cpe:2.3:a:calmkart:django-sso-server:*:*:*:*:*:*:*:*

History

05 Jun 2025, 19:39

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-18 20:15

Updated : 2025-06-05 19:39


NVD link : CVE-2025-4894

Mitre link : CVE-2025-4894

CVE.ORG link : CVE-2025-4894


JSON object : View

Products Affected

calmkart

  • django-sso-server
CWE
CWE-310

Cryptographic Issues

CWE-326

Inadequate Encryption Strength