jsrsasign is vulnerable to Insecure Randomness
75
High Risk
Affected versions of this package are vulnerable to the use of a cryptographically insecure or improperly selected random number generator in certain environments, including Node.js ≥ 19 and modern browsers. The affected logic in SecureRandom may fall back to or incorrectly select a non-cryptographic RNG, leading to generation of predictable values for security-sensitive operations such as key generation, signatures, or nonces. An attacker able to exploit this weakness can predict or brute-force generated values, potentially compromising cryptographic guarantees and enabling further attacks.
You are affected if you are using a version that falls within the vulnerable range.
jsrsasign is vulnerable to Insecure Randomness in versions 4.1.2 - 11.1.1.
Upgrade the jsrsasign library to the patch version.
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant