CVE-2021-23566 – nanoid
Package
Manager: npm
Name: nanoid
Vulnerable Version: >=3.0.0 <3.1.31
Severity
Level: Medium
CVSS v3.1: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS v4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
EPSS: 0.00033 pctl0.08066
Details
Exposure of Sensitive Information to an Unauthorized Actor in nanoid The package nanoid from 3.0.0, before 3.1.31, are vulnerable to Information Exposure via the valueOf() function which allows to reproduce the last id generated.
Metadata
Created: 2022-01-21T23:57:06Z
Modified: 2022-03-18T13:15:55Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/01/GHSA-qrpm-p2h7-hrv2/GHSA-qrpm-p2h7-hrv2.json
CWE IDs: ["CWE-200"]
Alternative ID: GHSA-qrpm-p2h7-hrv2
Finding: F038
Auto approve: 1