Description
node-uuid before 1.4.4 uses insufficiently random data to create a GUID, which could make it easier for attackers to have unspecified impact via brute force guessing.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-0358 | node-uuid before 1.4.4 uses insufficiently random data to create a GUID, which could make it easier for attackers to have unspecified impact via brute force guessing. |
Github GHSA |
GHSA-265q-28rp-chq5 | Insecure Entropy Source - Math.random() in node-uuid |
References
History
Wed, 07 Oct 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-10-07T20:07:29.354Z
Reserved: 2016-04-13T00:00:00.000Z
Link: CVE-2015-8851
Updated: 2024-08-06T08:29:22.071Z
Status : Modified
Published: 2020-01-30T21:15:14.653
Modified: 2026-10-07T21:16:59.953
Link: CVE-2015-8851
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-331
Insufficient Entropy
EUVD
Github GHSA