GHSA-6qqf-vvcr-7qrv

Suggest an improvement
Source
https://github.com/advisories/GHSA-6qqf-vvcr-7qrv
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/05/GHSA-6qqf-vvcr-7qrv/GHSA-6qqf-vvcr-7qrv.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-6qqf-vvcr-7qrv
Published
2019-05-23T09:27:22Z
Modified
2020-08-31T18:34:48Z
Summary
Cryptographically Weak PRNG in generate-password
Details

Affected versions of generate-password generate random values that are biased towards certain characters depending on the chosen character sets. This may result in guessable passwords.

Recommendation

Update to version 1.4.1 or later.

Database specific
{
    "cwe_ids":  [
        "CWE-338"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2019-05-23T07:38:39Z",
    "nvd_published_at":  null,
    "severity":  "MODERATE"
}
References

Affected packages

npm / generate-password

Package

Name
generate-password
View open source insights on deps.dev
Purl
pkg:npm/generate-password

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.4.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/05/GHSA-6qqf-vvcr-7qrv/GHSA-6qqf-vvcr-7qrv.json"