Описание
The crypto-js package before 3.2.1 for Node.js generates random numbers by concatenating the string "0." with an integer, which makes the output more predictable than necessary.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| cryptojs | removed | package | ||
| cryptojs | postponed | bookworm | package | |
| cryptojs | postponed | bullseye | package |
Примечания
https://security.snyk.io/vuln/SNYK-JS-CRYPTOJS-548472
Fixed by: https://github.com/brix/crypto-js/commit/103304018778513052b3560f12a7812f4543e392 (3.2.1)
EPSS
Процентиль: 63%
0.01075
Низкий
Связанные уязвимости
CVSS3: 5.3
ubuntu
около 3 лет назад
The crypto-js package before 3.2.1 for Node.js generates random numbers by concatenating the string "0." with an integer, which makes the output more predictable than necessary.
CVSS3: 5.3
nvd
около 3 лет назад
The crypto-js package before 3.2.1 for Node.js generates random numbers by concatenating the string "0." with an integer, which makes the output more predictable than necessary.
EPSS
Процентиль: 63%
0.01075
Низкий