Vulnerabilities/

Cryptographically Weak PRNG in generate-password

Severity:
Medium

Description

Affected versions of generate-password generate random values that are biased towards certain characters depending on the chosen character sets. This may result in guessable passwords.

Recommendation

Update the generate-password package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
generate-password
Anything's wrong? Let us know Last updated on January 09, 2023

This issue is available in SmartScanner Professional

See Pricing