jsrsasign is vulnerable to Insecure Randomness
75
High Risk
Affected versions of this package are vulnerable to the use of a cryptographically insecure or improperly selected random number generator in certain environments, including Node.js ≥ 19 and modern browsers. The affected logic in SecureRandom may fall back to or incorrectly select a non-cryptographic RNG, leading to generation of predictable values for security-sensitive operations such as key generation, signatures, or nonces. An attacker able to exploit this weakness can predict or brute-force generated values, potentially compromising cryptographic guarantees and enabling further attacks.
You are affected if you are using a version that falls within the vulnerable range.
jsrsasign is vulnerable to Insecure Randomness in versions 4.1.2 - 11.1.1.
Upgrade the jsrsasign library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant