Candidate: CVE-2015-8851 PublicDate: 2020-01-30 21:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8851 Description: node-uuid before 1.4.4 uses insufficiently random data to create a GUID, which could make it easier for attackers to have unspecified impact via brute force guessing. Ubuntu-Description: Notes: msalvatore> Introduced in commit 319dc6e2e75f8ff57e9e708e2187bdabba6ca86a Bugs: https://github.com/broofa/node-uuid/issues/108 https://github.com/broofa/node-uuid/issues/118 https://github.com/broofa/node-uuid/issues/122 Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N [7.5 HIGH] Patches_node-uuid: upstream: https://github.com/broofa/node-uuid/commit/672f3834ed02c798aa021c618d0a5666c8da000d upstream_node-uuid: released (1.4.4) precise_node-uuid: ignored (reached end-of-life) precise/esm_node-uuid: DNE (precise was needed) trusty_node-uuid: not-affected (code not present) trusty/esm_node-uuid: not-affected (code not present) vivid/stable-phone-overlay_node-uuid: DNE vivid/ubuntu-core_node-uuid: DNE wily_node-uuid: ignored (reached end-of-life) xenial_node-uuid: not-affected (code not present) yakkety_node-uuid: ignored (reached end-of-life) zesty_node-uuid: ignored (reached end-of-life) artful_node-uuid: ignored (reached end-of-life) bionic_node-uuid: not-affected (1.4.7-5) devel_node-uuid: not-affected (1.4.7-5)