Vulnerabilities/

Insecure random number generation in keypair

Severity:
High

Description

A bug in the pseudo-random number generator used by keypair versions up to and including 1.0.3 could allow for weak RSA key generation. This could enable an attacker to decrypt confidential messages or gain authorized access to an account belonging to the victim. We recommend replacing any RSA keys that were generated using keypair version 1.0.

Recommendation

Update the keypair package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
keypair
Anything's wrong? Let us know Last updated on February 01, 2023

This issue is available in SmartScanner Professional

See Pricing