c3js / c3js/c3

Insecure Randomness for the useof Math.random() in redrawBarForSubchart, redrawLineForSubchart and redrawAreaForSubchart(security vulnerability)

Open
#2,874 2 comments 1 reaction 0 assignees View on GitHub
Dominant language
JavaScript
Stars
9.3k
Forks
1.4k
Avg merge
6d 16h
Merged PRs (30d)
1

Description

* **C3 version**: v7.0.0
* **D3 version**: v5.0.0
* **Browser**: Chrome
* **OS**: Windows

Since Math.random could potentially return the same value twice and it is not cryptographically secure causing the insecure randomness when we scan the code in the fortify tool.

Please confirm if there is any future plan to remove Math.random and use cryptographically secure code for getting random values.
just by using crypto API
```
const myArray = new Uint32Array(10);
crypto.getRandomValues(myArray);
```

1. redrawBarForSubchart: https://github.com/c3js/c3/blob/master/c3.esm.js#L12493
2. redrawLineForSubchart: https://github.com/c3js/c3/blob/master/c3.esm.js#L12526
3. redrawAreaForSubchart: https://github.com/c3js/c3/blob/master/c3.esm.js#L12562

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.