Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-265q-28rp-chq5

Опубликовано: 16 апр. 2020
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Insecure Entropy Source - Math.random() in node-uuid

Affected versions of node-uuid consistently fall back to using Math.random as an entropy source instead of crypto, which may result in guessable UUID's.

Recommendation

Update to version 1.4.4 or later.

Пакеты

Наименование

node-uuid

npm
Затронутые версииВерсия исправления

< 1.4.4

1.4.4

EPSS

Процентиль: 64%
0.00477
Низкий

7.5 High

CVSS3

Дефекты

CWE-331

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 6 лет назад

node-uuid before 1.4.4 uses insufficiently random data to create a GUID, which could make it easier for attackers to have unspecified impact via brute force guessing.

redhat
почти 10 лет назад

node-uuid before 1.4.4 uses insufficiently random data to create a GUID, which could make it easier for attackers to have unspecified impact via brute force guessing.

CVSS3: 7.5
nvd
около 6 лет назад

node-uuid before 1.4.4 uses insufficiently random data to create a GUID, which could make it easier for attackers to have unspecified impact via brute force guessing.

CVSS3: 7.5
debian
около 6 лет назад

node-uuid before 1.4.4 uses insufficiently random data to create a GUI ...

EPSS

Процентиль: 64%
0.00477
Низкий

7.5 High

CVSS3

Дефекты

CWE-331