MEDIUM5.5
GHSA-qrpm-p2h7-hrv2
Exposure of Sensitive Information to an Unauthorized Actor in nanoid
Quick fix
GHSA-qrpm-p2h7-hrv2 — nanoid: upgrade to the fixed version with the command below.
npm install nanoid@3.1.31Details
The package nanoid from 3.0.0, before 3.1.31, are vulnerable to Information Exposure via the valueOf() function which allows to reproduce the last id generated.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2021-23566[ADVISORY]
- https://github.com/ai/nanoid/pull/328[WEB]
- https://github.com/ai/nanoid/commit/2b7bd9332bc49b6330c7ddb08e5c661833db2575[WEB]
- https://gist.github.com/artalar/bc6d1eb9a3477d15d2772e876169a444[WEB]
- https://github.com/ai/nanoid[PACKAGE]
- https://lists.debian.org/debian-lts-announce/2024/12/msg00025.html[WEB]
- https://lists.debian.org/debian-lts-announce/2025/01/msg00006.html[WEB]
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-2332550[WEB]
- https://snyk.io/vuln/SNYK-JS-NANOID-2332193[WEB]