{"id":"GHSA-3fmq-x9q6-wm39","summary":"random_compat Uses insecure CSPRNG","details":"random_compat versions prior to 2.0 are affected by a security vulnerability related to the insecure usage of Cryptographically Secure Pseudo-Random Number Generators (CSPRNG). The affected versions use openssl_random_pseudo_bytes(), which may result in insufficient entropy and compromise the security of generated random numbers.","modified":"2024-12-02T05:42:56.201685Z","published":"2024-05-17T23:27:19Z","database_specific":{"github_reviewed_at":"2024-05-17T23:27:19Z","nvd_published_at":null,"cwe_ids":["CWE-331"],"severity":"LOW","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/paragonie/random_compat/issues/96"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/paragonie/random_compat/2016-03-16.yaml"},{"type":"PACKAGE","url":"https://github.com/paragonie/random_compat"}],"affected":[{"package":{"name":"paragonie/random_compat","ecosystem":"Packagist","purl":"pkg:composer/paragonie/random_compat"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.0"}]}],"versions":["0.9.0","0.9.1","0.9.2","0.9.3","0.9.4","0.9.5","1.0.10","1.0.2","1.0.3","1.0.4","1.0.5","1.0.6","1.0.7","1.0.8","1.0.9","1.1.0","1.1.1","1.1.2","1.1.3","1.1.4","1.1.5","1.1.6","v0.9.7","v1.0.0","v1.0.1","v1.2.0","v1.2.1","v1.2.2","v1.2.3","v1.3.0","v1.3.1","v1.4.0","v1.4.1","v1.4.2","v1.4.3"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/05/GHSA-3fmq-x9q6-wm39/GHSA-3fmq-x9q6-wm39.json"}}],"schema_version":"1.9.0"}