PT-2018-6058 · Facebook+1 · React-Native-Meteor-Oauth+1

Publicado

2018-06-04

·

Atualizado

2019-10-09

·

CVE-2017-16028

CVSS v3.1

5.3

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions: react-native-meteor-oauth (affected versions not specified) randomatic versions prior to 3.0.0
Description: The issue concerns the generation of random values using a non-cryptographically strong pseudo-random number generator, which may result in predictable values instead of random values as intended. This affects the oauth Random Token generation in react-native-meteor-oauth and the random values generated by randomatic.
Recommendations: For react-native-meteor-oauth, at the moment, there is no information about a newer version that contains a fix for this vulnerability. For randomatic versions prior to 3.0.0, update to version 3.0.0 or later.

Use of Insufficiently Random Values

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-16028
GHSA-6G33-F262-XJP4

Produtos afetados

Randomatic
React-Native-Meteor-Oauth