VDB
Sign up
CRITICAL9.8

GHSA-rq8g-5pc5-wrhr

Insufficient Entropy in cryptiles

Quick fix

GHSA-rq8g-5pc5-wrhr — cryptiles: upgrade to the fixed version with the command below.

npm install cryptiles@4.1.2

Details

Versions of `cryptiles` prior to 4.1.2 are vulnerable to Insufficient Entropy. The `randomDigits()` method does not provide sufficient entropy and its generates digits that are not evenly distributed.

## Recommendation

Upgrade to version 4.1.2. The package is deprecated and has been moved to `@hapi/cryptiles` and it is strongly recommended to use the maintained package.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/cryptiles
Introduced in: 4.0.0Fixed in: 4.1.2
Fixnpm install cryptiles@4.1.2
npm/cryptiles
Introduced in: 3.1.0Fixed in: 3.1.3
Fixnpm install cryptiles@3.1.3

References