Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-36732

Опубликовано: 12 июн. 2023
Источник: debian
EPSS Низкий

Описание

The crypto-js package before 3.2.1 for Node.js generates random numbers by concatenating the string "0." with an integer, which makes the output more predictable than necessary.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
cryptojsremovedpackage
cryptojspostponedbookwormpackage
cryptojspostponedbullseyepackage

Примечания

  • https://security.snyk.io/vuln/SNYK-JS-CRYPTOJS-548472

  • Fixed by: https://github.com/brix/crypto-js/commit/103304018778513052b3560f12a7812f4543e392 (3.2.1)

EPSS

Процентиль: 63%
0.01075
Низкий

Связанные уязвимости

CVSS3: 5.3
ubuntu
около 3 лет назад

The crypto-js package before 3.2.1 for Node.js generates random numbers by concatenating the string "0." with an integer, which makes the output more predictable than necessary.

CVSS3: 5.3
nvd
около 3 лет назад

The crypto-js package before 3.2.1 for Node.js generates random numbers by concatenating the string "0." with an integer, which makes the output more predictable than necessary.

CVSS3: 5.3
github
около 3 лет назад

crypto-js uses insecure random numbers

EPSS

Процентиль: 63%
0.01075
Низкий