CVE-2024-55565

nanoid (aka Nano ID) before 5.0.9 mishandles non-integer values. 3.3.8 is also a fixed version.
Infinite Loop
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.3 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
mitreCNA
---
---
CISA-ADPADP
4.3 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 1%
Debian logo
Debian Releases
Debian Product
Codename
node-mocha
bullseye
vulnerable
bullseye (security)
8.2.1+ds1+~cs29.4.27-3+deb11u1
fixed
bookworm
10.1.0+ds1+~cs29.3.1-1
fixed
sid
10.7.2+ds1+~cs33.1.11-2
fixed
trixie
10.7.2+ds1+~cs33.1.11-2
fixed
node-postcss
bullseye
vulnerable
bullseye (security)
8.2.1+~cs5.3.23-8+deb11u1
fixed
bookworm
8.4.20+~cs8.0.23-1+deb12u1
fixed
sid
8.4.49+~cs9.2.32-1
fixed
trixie
8.4.49+~cs9.2.32-1
fixed