{"id":"GHSA-3fmq-x9q6-wm39","aliases":[],"url":"https://o3.security/vulnerability/GHSA-3fmq-x9q6-wm39","summary":"random_compat Uses insecure CSPRNG","details":"random_compat versions prior to 2.0 are affected by a security vulnerability related to the insecure usage of Cryptographically Secure Pseudo-Random Number Generators (CSPRNG). The affected versions use openssl_random_pseudo_bytes(), which may result in insufficient entropy and compromise the security of generated random numbers.","published":"2024-05-17T23:27:19Z","modified":"2024-12-02T05:42:56.201685Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"paragonie/random_compat","fixedVersion":"2.0"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/paragonie/random_compat/issues/96"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/paragonie/random_compat/2016-03-16.yaml"},{"type":"PACKAGE","url":"https://github.com/paragonie/random_compat"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-12-02T05:42:56.201685Z"}}