CVE-2019-25061: Random Password Generator Project Random Password Generator
High severity, CVSS 7.5. EPSS: 1.9% chance of exploitation in the next 30 days.
The random_password_generator (aka RandomPasswordGenerator) gem through 1.0.0 for Ruby uses Kernel#rand to generate passwords, which, due to its cyclic nature, can facilitate password prediction.
Affected products
- Random Password Generator Project Random Password Generator: up to and including 1.0.0
Published 2022-05-18. Last modified 2026-06-17.