Description
Affected versions of randomatic generate random values using a cryptographically weak psuedo-random number generator. This may result in predictable values instead of random values as intended.
Recommendation
Update the randomatic package to the latest compatible version. Followings are version details:
- Affected version(s): < 3.0.0
- Patched version(s): 3.0.0
References
Could your website be exposed too?
SmartScanner can check your website for Cryptographically Weak PRNG in randomatic and gives you actionable findings to investigate.
Start a free scanRelated Issues
- ejs vulnerable to DoS due to weak input validation - CVE-2017-1000189
- ejs is vulnerable to remote code execution due to weak input validation - CVE-2017-1000228
- superagent vulnerable to zip bomb attacks - CVE-2017-16129
- Cross-Site Scripting in i18next - i18next - CVE-2017-16010
You might also like:
See something that needs correcting? Let us knowUpdated September 08, 2023


