"In Net::OAuth::Client in the Net::OAuth package before 0.29 for Perl, the default nonce is a 32-bit integer generated from the built-in rand() function, which is not cryptographically strong."
The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=5ab2f76de326ede3dcaaeea3ffc546382785f200 commit 5ab2f76de326ede3dcaaeea3ffc546382785f200 Author: Sam James <sam@gentoo.org> AuthorDate: 2025-01-22 06:16:12 +0000 Commit: Sam James <sam@gentoo.org> CommitDate: 2025-01-22 06:16:12 +0000 dev-perl/Net-OAuth: add 0.300.0 Bug: https://bugs.gentoo.org/948522 Signed-off-by: Sam James <sam@gentoo.org> dev-perl/Net-OAuth/Manifest | 1 + dev-perl/Net-OAuth/Net-OAuth-0.300.0.ebuild | 31 +++++++++++++++++++++++++++++ 2 files changed, 32 insertions(+)