{"id":"GHSA-rq8g-5pc5-wrhr","summary":"Insufficient Entropy in cryptiles","details":"Versions of `cryptiles` prior to 4.1.2 are vulnerable to Insufficient Entropy. The `randomDigits()` method does not provide sufficient entropy and its generates digits that are not evenly distributed.\n\n\n## Recommendation\n\nUpgrade to version 4.1.2. The package is deprecated and has been moved to `@hapi/cryptiles` and it is strongly recommended to use the maintained package.","aliases":["CVE-2018-1000620"],"modified":"2026-06-08T16:00:10.626353489Z","published":"2018-09-11T18:22:50Z","database_specific":{"nvd_published_at":"2018-07-09T20:29:00Z","cwe_ids":["CWE-331"],"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2020-06-16T21:55:29Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2018-1000620"},{"type":"WEB","url":"https://github.com/hapijs/cryptiles/issues/34"},{"type":"WEB","url":"https://github.com/hapijs/cryptiles/issues/35"},{"type":"WEB","url":"https://github.com/hapijs/cryptiles/commit/6bdcd0f6ee8ade96e7b30350bad39ee0c2ef0f9b"},{"type":"WEB","url":"https://github.com/hapijs/cryptiles/commit/9332d4263a32b84e76bf538d7470d01ea63fa047"},{"type":"WEB","url":"https://github.com/hapijs/cryptiles/commit/cb6bd642816e0cb8341d2b3896fd9e7c57e94f56"},{"type":"PACKAGE","url":"https://github.com/hapijs/cryptiles"},{"type":"WEB","url":"https://github.com/nodejs/security-wg/blob/master/vuln/npm/476.json"},{"type":"WEB","url":"https://www.npmjs.com/advisories/1464"},{"type":"WEB","url":"https://www.npmjs.com/advisories/720"}],"affected":[{"package":{"name":"cryptiles","ecosystem":"npm","purl":"pkg:npm/cryptiles"},"ranges":[{"type":"SEMVER","events":[{"introduced":"4.0.0"},{"fixed":"4.1.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/09/GHSA-rq8g-5pc5-wrhr/GHSA-rq8g-5pc5-wrhr.json"}},{"package":{"name":"cryptiles","ecosystem":"npm","purl":"pkg:npm/cryptiles"},"ranges":[{"type":"SEMVER","events":[{"introduced":"3.1.0"},{"fixed":"3.1.3"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/09/GHSA-rq8g-5pc5-wrhr/GHSA-rq8g-5pc5-wrhr.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}