vulnerability alert CVE-2015-8851

Node.js uuid: predictable identifier

Synthesis of the vulnerability

An attacker can guess identifiers generated by Node.js uuid.
Impacted products: Nodejs Modules ~ not comprehensive.
Severity of this bulletin: 1/4.
Consequences of an intrusion: data reading.
Hacker's origin: document.
Creation date: 29/03/2016.
Références of this threat: CVE-2015-8851, VIGILANCE-VUL-19251.

Description of the vulnerability

The uuid module can be installed on Node.js.

However, its random generator uses Math.random(), which does not provide sufficient entropy.

An attacker can therefore guess identifiers generated by Node.js uuid.
