Описание
The crypto-js package before 3.2.1 for Node.js generates random numbers by concatenating the string "0." with an integer, which makes the output more predictable than necessary.
Ссылки
- Release Notes
- Issue TrackingVendor Advisory
- Issue TrackingPatchVendor Advisory
- Patch
- Third Party Advisory
- Release Notes
- Issue TrackingVendor Advisory
- Issue TrackingPatchVendor Advisory
- Patch
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 3.2.1 (исключая)
cpe:2.3:a:crypto-js_project:crypto-js:*:*:*:*:*:*:*:*
EPSS
Процентиль: 63%
0.01075
Низкий
5.3 Medium
CVSS3
Дефекты
CWE-330
CWE-331
Связанные уязвимости
CVSS3: 5.3
ubuntu
около 3 лет назад
The crypto-js package before 3.2.1 for Node.js generates random numbers by concatenating the string "0." with an integer, which makes the output more predictable than necessary.
CVSS3: 5.3
debian
около 3 лет назад
The crypto-js package before 3.2.1 for Node.js generates random number ...
EPSS
Процентиль: 63%
0.01075
Низкий
5.3 Medium
CVSS3
Дефекты
CWE-330
CWE-331