The function used to generate random nonces was not sufficiently cryptographically complex. As a result values may be predictable and tokens may be forgable.
Users should upgrade to version 5.0 immediately
None.
{
"nvd_published_at": "2022-07-15T18:15:00Z",
"severity": "HIGH",
"github_reviewed_at": "2022-07-15T20:55:46Z",
"github_reviewed": true,
"cwe_ids": [
"CWE-327",
"CWE-330"
]
}