Insecure Random Token Generation in react-native-meteor-oauth

Insecure Random Token Generation in react-native-meteor-oauth

CVE-2017-16028 · MEDIUM Severity

AV:N/AC:L/AU:N/C:P/I:N/A:N

react-native-meteor-oauth is a library for Oauth2 login to a Meteor server in React Native. The oauth Random Token is generated using a non-cryptographically strong RNG (Math.random()).

Learn more about our Cis Benchmark Audit For Server Software.