VDB
KO
CRITICAL 9.8

GHSA-rq8g-5pc5-wrhr

Insufficient Entropy in cryptiles

Details

Versions of `cryptiles` prior to 4.1.2 are vulnerable to Insufficient Entropy. The `randomDigits()` method does not provide sufficient entropy and its generates digits that are not evenly distributed.

## Recommendation

Upgrade to version 4.1.2. The package is deprecated and has been moved to `@hapi/cryptiles` and it is strongly recommended to use the maintained package.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / cryptiles
Introduced in: 4.0.0 Fixed in: 4.1.2
Fix npm install cryptiles@4.1.2
npm / cryptiles
Introduced in: 3.1.0 Fixed in: 3.1.3
Fix npm install cryptiles@3.1.3

References