Description
Affected versions of randomatic generate random values using a cryptographically weak psuedo-random number generator. This may result in predictable values instead of random values as intended.
Recommendation
Update the randomatic package to the latest compatible version. Followings are version details:
- Affected version(s): < 3.0.0
- Patched version(s): 3.0.0
References
Related Issues
- ejs vulnerable to DoS due to weak input validation - CVE-2017-1000189
- ejs is vulnerable to remote code execution due to weak input validation - CVE-2017-1000228
- superagent vulnerable to zip bomb attacks - CVE-2017-16129
- Cross-Site Scripting in i18next - i18next - CVE-2017-16010
You might also like:
- Tags:
- npm
- randomatic
Anything's wrong? Let us know Last updated on September 08, 2023


