Insufficient Entropy in cryptiles
Critical severity
GitHub Reviewed
Published
Sep 11, 2018
to the GitHub Advisory Database
•
Updated Nov 29, 2023
Description
Published by the National Vulnerability Database
Jul 9, 2018
Published to the GitHub Advisory Database
Sep 11, 2018
Reviewed
Jun 16, 2020
Last updated
Nov 29, 2023
Versions of
cryptiles
prior to 4.1.2 are vulnerable to Insufficient Entropy. TherandomDigits()
method does not provide sufficient entropy and its generates digits that are not evenly distributed.Recommendation
Upgrade to version 4.1.2. The package is deprecated and has been moved to
@hapi/cryptiles
and it is strongly recommended to use the maintained package.References