Lucene search

K
nodejsJonathan LeitschuhNODEJS:1187
HistorySep 26, 2019 - 9:24 p.m.

Cryptographically Weak PRNG

2019-09-2621:24:25
Jonathan Leitschuh
www.npmjs.com
21

EPSS

0.02

Percentile

89.2%

Overview

Versions of generator-jhipster use a Cryptographically Weak PRNG that may lead to account takeover. The package uses a cryptographically insecure method to generate password reset links, which allows an attacker to guess password reset links and takeover accounts.

Recommendation

Update to version 6.3.0 or later.

References

EPSS

0.02

Percentile

89.2%