Описание
The crypto-js package before 3.2.1 for Node.js generates random numbers by concatenating the string "0." with an integer, which makes the output more predictable than necessary.
Ссылки
- Release Notes
- Issue TrackingVendor Advisory
- Issue TrackingPatchVendor Advisory
- Patch
- Third Party Advisory
- Release Notes
- Issue TrackingVendor Advisory
- Issue TrackingPatchVendor Advisory
- Patch
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 3.2.1 (исключая)
cpe:2.3:a:crypto-js_project:crypto-js:*:*:*:*:*:*:*:*
EPSS
Процентиль: 77%
0.01061
Низкий
5.3 Medium
CVSS3
Дефекты
CWE-330
CWE-331
Связанные уязвимости
CVSS3: 5.3
ubuntu
больше 2 лет назад
The crypto-js package before 3.2.1 for Node.js generates random numbers by concatenating the string "0." with an integer, which makes the output more predictable than necessary.
EPSS
Процентиль: 77%
0.01061
Низкий
5.3 Medium
CVSS3
Дефекты
CWE-330
CWE-331