CVE-2013-4347: Urbanairship Python-OAUTH2
Medium severity, CVSS 5.8. EPSS: 2.5% chance of exploitation in the next 30 days.
The (1) make_nonce, (2) generate_nonce, and (3) generate_verifier functions in SimpleGeo python-oauth2 uses weak random numbers to generate nonces, which makes it easier for remote attackers to guess the nonce via a brute force attack.
Affected products
- Urbanairship Python-OAUTH2: affected versions not specified
Published 2014-05-20. Last modified 2026-06-16.