Vulnerabilities/

crypto-js uses insecure random numbers

Severity:
Medium

Description

The crypto-js package before 3.2.1 for Node.js generates random numbers by concatenating the string “0.” with an integer, which makes the output more predictable than necessary.

Recommendation

Update the crypto-js package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
crypto-js
Anything's wrong? Let us know Last updated on January 06, 2025

This issue is available in SmartScanner Professional

See Pricing