The package nanoid from 3.0.0 and before 3.1.31 are vulnerable to Information Exposure via the valueOf() function which allows to reproduce the last id generated.
Metrics
Affected Vendors & Products
References
History
Sun, 08 Sep 2024 18:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
CPEs | cpe:/a:redhat:acm:2.4::el8 |
Mon, 19 Aug 2024 22:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
CPEs |
MITRE
Status: PUBLISHED
Assigner: snyk
Published: 2022-01-14T20:05:21.597945Z
Updated: 2024-09-17T03:58:57.444Z
Reserved: 2021-01-08T00:00:00
Link: CVE-2021-23566
Vulnrichment
No data.
NVD
Status : Modified
Published: 2022-01-14T20:15:10.093
Modified: 2024-11-21T05:51:50.010
Link: CVE-2021-23566
Redhat