ZeroHour

CVE-2021-23566

PoC ×4
CVSS 3.1
5.5 medium
EPSS
<1%p37
Published
()
Modified
Description

The package nanoid from 3.0.0 and before 3.1.31 are vulnerable to Information Exposure via the valueOf() function which allows to reproduce the last id generated.

Vendors
nanoid project
Products
nanoid
Weakness
CWE-704
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.