logo

CVE-2021-23566 nanoid

Package

Manager: npm
Name: nanoid
Vulnerable Version: >=3.0.0 <3.1.31

Severity

Level: Medium

CVSS v3.1: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CVSS v4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

EPSS: 0.00033 pctl0.08066

Details

Exposure of Sensitive Information to an Unauthorized Actor in nanoid The package nanoid from 3.0.0, before 3.1.31, are vulnerable to Information Exposure via the valueOf() function which allows to reproduce the last id generated.

Metadata

Created: 2022-01-21T23:57:06Z
Modified: 2022-03-18T13:15:55Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/01/GHSA-qrpm-p2h7-hrv2/GHSA-qrpm-p2h7-hrv2.json
CWE IDs: ["CWE-200"]
Alternative ID: GHSA-qrpm-p2h7-hrv2
Finding: F038
Auto approve: 1