Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-1000620

Опубликовано: 19 июл. 2018
Источник: redhat
CVSS3: 3.7
EPSS Низкий

Описание

Eran Hammer cryptiles version 4.1.1 earlier contains a CWE-331: Insufficient Entropy vulnerability in randomDigits() method that can result in An attacker is more likely to be able to brute force something that was supposed to be random.. This attack appear to be exploitable via Depends upon the calling application.. This vulnerability appears to have been fixed in 4.1.2.

A flaw was found in the nodejs-cryptiles library prior to version 4.1.2. Previous versions do not implement cryptographically secure randomness resulting in the randomDigits() function returning a pseudo-random data string biased to certain digits. An attacker could exploit this to guess the generated digits.

Отчет

Red Hat Quay imports nodejs-crypttiles as a development dependency. Reducing the impact of Red Hat Quay to low.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Mobile Application Platform 4nodejs-cryptilesNot affected
Red Hat OpenShift Enterprise 3nodejs-cryptilesNot affected
Red Hat Quay 3quay/quay-rhel8Fix deferred
Red Hat Software Collectionsrh-nodejs6-nodejs-cryptilesNot affected
Red Hat Software Collectionsrh-nodejs8-nodejsNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-330
https://bugzilla.redhat.com/show_bug.cgi?id=1608153nodejs-cryptiles: Insecure randomness causes the randomDigits() function returns a pseudo-random data string biased to certain digits

EPSS

Процентиль: 57%
0.00355
Низкий

3.7 Low

CVSS3

Связанные уязвимости

CVSS3: 9.8
nvd
больше 7 лет назад

Eran Hammer cryptiles version 4.1.1 earlier contains a CWE-331: Insufficient Entropy vulnerability in randomDigits() method that can result in An attacker is more likely to be able to brute force something that was supposed to be random.. This attack appear to be exploitable via Depends upon the calling application.. This vulnerability appears to have been fixed in 4.1.2.

CVSS3: 9.8
github
больше 7 лет назад

Insufficient Entropy in cryptiles

EPSS

Процентиль: 57%
0.00355
Низкий

3.7 Low

CVSS3

Уязвимость CVE-2018-1000620