CVE-2013-4347: Urbanairship Python-OAUTH2

Medium severity, CVSS 5.8. EPSS: 2.5% chance of exploitation in the next 30 days.

The (1) make_nonce, (2) generate_nonce, and (3) generate_verifier functions in SimpleGeo python-oauth2 uses weak random numbers to generate nonces, which makes it easier for remote attackers to guess the nonce via a brute force attack.

Affected products

Published 2014-05-20. Last modified 2026-06-16.