CVE-2017-16028: Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)
(updated )
The oauth Random Token is generated using a non-cryptographically strong RNG (Math.random()
).
References
Detect and mitigate CVE-2017-16028 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →