node-redlock is vulnerable to Insecure Randomness
20
Low Risk
Affected versions of this package are vulnerable to Insecure Randomness in Lock Tokens due to the use of Math.random() for generating lock tokens, which is not cryptographically secure and produces predictable values. An attacker could exploit this by predicting the lock tokens to bypass authentication mechanisms, potentially leading to unauthorized access, privilege escalation, or data integrity issues.
You are affected if you are using a version that falls within the vulnerable range.
node-redlock is vulnerable to Insecure Randomness in versions 1.1.0 - 2.2.1.
Upgrade the node-redlock library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant