CVE-2020-36732

MEDIUM5.3EPSS 0.88%

crypto-js uses insecure random numbers

Published: 6/12/2023Modified: 3/16/2026

Description

The crypto-js package 3.2.0 for Node.js generates random numbers by concatenating the string "0." with an integer, which makes the output more predictable than necessary.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM5.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

References (10)