Lucene search

K
nodejsMicrosoft Vulnerability ResearchNODEJS:720
HistoryNov 01, 2018 - 6:32 p.m.

Insufficient Entropy

2018-11-0118:32:48
Microsoft Vulnerability Research
www.npmjs.com
26

EPSS

0.002

Percentile

58.6%

Overview

Versions of cryptiles from version 3.1.0 through 3.1.2, and versions 4.0.0 to version 4.1.1 are vulnerable to insufficient entropy. The randomDigits method generates digits that lack a perfect distribution over enough attempts.

Recommendation

Update to version 3.1.3 or 4.1.2 or later.

References

EPSS

0.002

Percentile

58.6%