CVE-2021-23566
14.01.2022, 20:15
The package nanoid from 3.0.0 and before 3.1.31 are vulnerable to Information Exposure via the valueOf() function which allows to reproduce the last id generated.Enginsight
| Vendor | Product | Version |
|---|---|---|
| nanoid_project | nanoid | 3.0.0 ≤ 𝑥 < 3.1.31 |
𝑥
= Vulnerable software versions
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| chromium-browser |
| ||||||||||||||||||||
| node-mocha |
| ||||||||||||||||||||
| node-postcss |
|
Common Weakness Enumeration
References