Lucene search

K
osvGoogleOSV:GHSA-2H3H-VW8R-82RP
HistoryMar 26, 2021 - 4:49 p.m.

Weak JSON Web Token in yapi-vendor

2021-03-2616:49:26
Google
osv.dev
10
weak jwt
yapi-vendor
cryptographically secure.

EPSS

0.001

Percentile

27.1%

Weak JSON Web Token (JWT) signing secret generation in YMFE YApi through 1.9.2 allows recreation of other users’ JWT tokens. This occurs because Math.random in Node.js is used as a source of randomness in jwt signing. Math.random does not provide cryptographically secure random numbers. This has been patched in version 1.9.3.

EPSS

0.001

Percentile

27.1%

Related for OSV:GHSA-2H3H-VW8R-82RP