CVE-2015-8851

Severity CVSS v4.0:
Pending analysis
Type:
CWE-331 Insufficient Entropy
Publication date:
30/01/2020
Last modified:
05/02/2020

Description

node-uuid before 1.4.4 uses insufficiently random data to create a GUID, which could make it easier for attackers to have unspecified impact via brute force guessing.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:node-uuid_project:node-uuid:*:*:*:*:*:node.js:*:* 1.4.4 (excluding)