Lucene search

K
cvelistHackeroneCVELIST:CVE-2017-16028
HistoryApr 26, 2018 - 12:00 a.m.

CVE-2017-16028

2018-04-2600:00:00
CWE-330
hackerone
www.cve.org

6.2 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

34.6%

react-native-meteor-oauth is a library for Oauth2 login to a Meteor server in React Native. The oauth Random Token is generated using a non-cryptographically strong RNG (Math.random()).

CNA Affected

[
  {
    "product": "react-native-meteor-oauth node module",
    "vendor": "HackerOne",
    "versions": [
      {
        "status": "affected",
        "version": "All versions"
      }
    ]
  }
]

6.2 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

34.6%

Related for CVELIST:CVE-2017-16028