VDB
Sign up
MEDIUM5.3

GHSA-3w3w-pxmm-2w2j

crypto-js uses insecure random numbers

Quick fix

GHSA-3w3w-pxmm-2w2j — crypto-js: upgrade to the fixed version with the command below.

npm install crypto-js@3.2.1

Details

The crypto-js package 3.2.0 for Node.js generates random numbers by concatenating the string "0." with an integer, which makes the output more predictable than necessary.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/crypto-js
Introduced in: 3.2.0Fixed in: 3.2.1
Fixnpm install crypto-js@3.2.1

References