jsrsasign is vulnerable to Insecure Randomness
75
High Risk
Affected versions of this package are vulnerable to the use of a cryptographically insecure or improperly selected random number generator in certain environments, including Node.js ≥ 19 and modern browsers. The affected logic in SecureRandom may fall back to or incorrectly select a non-cryptographic RNG, leading to generation of predictable values for security-sensitive operations such as key generation, signatures, or nonces. An attacker able to exploit this weakness can predict or brute-force generated values, potentially compromising cryptographic guarantees and enabling further attacks.
You are affected if you are using a version that falls within the vulnerable range.
jsrsasign is vulnerable to Insecure Randomness in versions 4.1.2 - 11.1.1.
Upgrade the jsrsasign library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant