cryptiles@4.0.2 vulnerabilities

General purpose crypto utilities

Direct Vulnerabilities

Known vulnerabilities in the cryptiles package. This does not include vulnerabilities belonging to this package’s dependencies.

Insecure Randomness

cryptiles is a package for general crypto utilities.

Affected versions of this package are vulnerable to Insecure Randomness. The randomDigits() method is supposed to return a cryptographically strong pseudo-random data string, but it was biased to certain digits. An attacker could be able to guess the created digits.

How to fix Insecure Randomness?

Upgrade to versions 3.1.3, 4.1.2 and higher.

>=3.1.0 <3.1.3 >=4.0.0 <4.1.2