Medium severity6.5NVD Advisory· Published Jul 25, 2022· Updated Jun 17, 2026
CVE-2021-23451
CVE-2021-23451
Description
The package otp-generator before 3.0.0 are vulnerable to Insecure Randomness due to insecure generation of random one-time passwords, which may allow a brute-force attack.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
otp-generatornpm | < 3.0.0 | 3.0.0 |
Affected products
2- cpe:2.3:a:otp-generator_project:otp-generator:*:*:*:*:*:node.js:*:*Range: <3.0.0
Patches
Vulnerability mechanics
References
5- github.com/Maheshkumar-Kakade/otp-generator/commit/b27de1ce439ae7f533cec26677e9698671275b70nvdPatchThird Party AdvisoryWEB
- security.snyk.io/vuln/SNYK-JS-OTPGENERATOR-1655480nvdIssue TrackingPatchThird Party AdvisoryWEB
- github.com/Maheshkumar-Kakade/otp-generator/issues/12nvdIssue TrackingThird Party AdvisoryWEB
- github.com/advisories/GHSA-6x93-h9g3-9phrghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2021-23451ghsaADVISORY
News mentions
0No linked articles in our index yet.