CVE-2018-1000620
ADVISORY - githubSummary
Versions of cryptiles prior to 4.1.2 are vulnerable to Insufficient Entropy. The randomDigits() method does not provide sufficient entropy and its generates digits that are not evenly distributed.
Recommendation
Upgrade to version 4.1.2. The package is deprecated and has been moved to @hapi/cryptiles and it is strongly recommended to use the maintained package.
EPSS Score: 0.00374 (0.584)
Common Weakness Enumeration (CWE)
ADVISORY - nist
Insufficient Entropy
ADVISORY - github
Insufficient Entropy
ADVISORY - gitlab
ADVISORY - redhat
Use of Insufficiently Random Values
NIST
CREATED
UPDATED
ADVISORY IDCVE-2018-1000620
EXPLOITABILITY SCORE
3.9
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)
CVSS SCORE
9.8criticalGitHub
CREATED
UPDATED
ADVISORY IDGHSA-rq8g-5pc5-wrhr
EXPLOITABILITY SCORE
3.9
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)
CVSS SCORE
9.8criticalRed Hat
CREATED
UPDATED
ADVISORY IDCVE-2018-1000620
EXPLOITABILITY SCORE
2.2
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)