๐Ÿ” CVE Alert

CVE-2020-36732

MEDIUM 5.3
CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th

The crypto-js package before 3.2.1 for Node.js generates random numbers by concatenating the string "0." with an integer, which makes the output more predictable than necessary.

Vendor n/a
Product n/a
Published Jun 12, 2023
Last Updated Jan 6, 2025
Stay Ahead of the Next One

Get instant alerts for n/a n/a

Be the first to know when new medium vulnerabilities affecting n/a n/a are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

n/a / n/a
n/a

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
security.snyk.io: https://security.snyk.io/vuln/SNYK-JS-CRYPTOJS-548472 github.com: https://github.com/brix/crypto-js/pull/257/commits/e4ac157d8b75b962d6538fc0b996e5d4d5a9466b github.com: https://github.com/brix/crypto-js/issues/254 github.com: https://github.com/brix/crypto-js/issues/256 github.com: https://github.com/brix/crypto-js/compare/3.2.0...3.2.1 security.netapp.com: https://security.netapp.com/advisory/ntap-20230706-0003/