QID 983759
QID 983759: Nodejs (npm) Security Update for cryptiles (GHSA-rq8g-5pc5-wrhr)
Versions of `cryptiles` prior to 4.1.2 are vulnerable to Insufficient Entropy. The `randomDigits()` method does not provide sufficient entropy and its generates digits that are not evenly distributed. ## Recommendation Upgrade to version 4.1.2. The package is deprecated and has been moved to `@hapi/cryptiles` and it is strongly recommended to use the maintained package.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-rq8g-5pc5-wrhr for updates pertaining to this vulnerability.
Vendor References
- GHSA-rq8g-5pc5-wrhr -
github.com/advisories/GHSA-rq8g-5pc5-wrhr
CVEs related to QID 983759
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-rq8g-5pc5-wrhr | cryptiles |
|