@firebase/util is vulnerable to Generation of Weak Initialization Vector
18
Low Risk
Affected versions of this package are affected by insecure randomness due to the use of Math.random() in a Firebase custom UUID function that could create significant security vulnerabilities. This weak random number generator enables potential attackers to predict UUIDs, which can lead to collisions and unauthorized access to resources.
You are affected if you are using a version that falls within the vulnerable range.
@firebase/util is vulnerable to Generation of Weak Initialization Vector in versions 1.6.2 - 1.10.2.
Upgrade the @firebase/util library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant