CVE-2017-16028
3Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 1.4%
exploitation probability
1.4%top 30% of all CVEs
observed exploitation
nono source reports it
react-native-meteor-oauth is a library for Oauth2 login to a Meteor server in React Native. The oauth Random Token is generated using a non-cryptographically strong RNG (Math.random()).
Affected products
HackerOne · react-native-meteor-oauth node module