CVE-2020-36732

CVSS 3.1 Score 5.3 of 10 (medium)

Details

Published Jun 12, 2023
Updated: Jan 6, 2025
CWE ID 330
CWE ID 331

Summary

CVE-2020-36732 is a vulnerability affecting the crypto-js package prior to version 3.2.1 used in Node.js. This issue arises due to the package's approach to generating random numbers, where the string "0." is concatenated with an integer. Consequently, the output becomes more predictable than desired, posing potential risks for applications relying on this functionality for secure operations. Users are advised to upgrade to the latest version of the crypto-js package to mitigate this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share