Math.random() use a security vulnerability?

18 views
Skip to first unread message

Mark McNally

unread,
Nov 13, 2017, 10:41:20 AM11/13/17
to Strophe
Hello, 

The Fortify SCA scanner flagged the use of Math.random() in strophe.js as being insecure.

This appeared as part of a of a new company requirement for our web apps to be free of Critical and High severity security vulnerabilities.

Can anyone comment on the validity of this claim in this context?

Thank you, 

Mark 


Reply all
Reply to author
Forward
0 new messages