Skip to main content

Insufficient Entropy in cryptiles

CVE-2018-1000620

  • cryptiles
  • org.webjars.npm:cryptiles
Severity High
Score 9.8/10

Summary

Eran Hammer cryptiles versions 3.1.0 through 3.1.2 and 4.0.0 through 4.1.1 contain an insufficient entropy vulnerability in the "randomDigits()" method that can result in an attacker being more likely to be able to brute force something that was supposed to be random.

  • LOW
  • NETWORK
  • HIGH
  • UNCHANGED
  • NONE
  • NONE
  • HIGH
  • HIGH

CWE-331 - Insufficient Entropy

The software uses an algorithm or scheme that produces insufficient entropy, leaving patterns or clusters of values that are more likely to occur than others.

Advisory Timeline

  • Published