Back

CRITICAL

nodejs: weak randomness in WebCrypto keygen

Published Dec 5, 2022

Description

A weak randomness in WebCrypto keygen vulnerability exists in Node.js 18 due to a change with EntropySource() in SecretKeyGenTraits::DoKeyGen() in src/crypto/crypto_keygen.cc. There are two problems with this: 1) It does not check the return value, it assumes EntropySource() always succeeds, but it can (and sometimes will) fail. 2) The random data returned byEntropySource() may not be cryptographically strong and therefore not suitable as keying material.

Affected products

Remediation

Red Hat statement

The vulnerability was introduced in NodeJS v15.0.0, Hence, NodeJS:14 package in RHEL-8 and RHSCL-3 are not affected.

Weaknesses (1)

References (11)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner hackerone
Published Dec 5, 2022
Updated Apr 30, 2025
Reserved Jul 6, 2022

CISA Vulnrichment

Updated Apr 24, 2025

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

Severity Important
Public date Sep 23, 2022
Bugzilla 2130517

ENISA EUVD

Assigner hackerone
Published Dec 5, 2022
Updated Apr 30, 2025

GitHub

No data