CVE-2021-23566

Related Vulnerabilities: CVE-2021-23566  

The package nanoid from 3.0.0 and before 3.1.31 are vulnerable to Information Exposure via the valueOf() function which allows to reproduce the last id generated.

Description

The MITRE CVE dictionary describes this issue as:

The package nanoid from 3.0.0 and before 3.1.31 are vulnerable to Information Exposure via the valueOf() function which allows to reproduce the last id generated.

Additional Information

  • Bugzilla 2050853: CVE-2021-23566 nanoid: Information disclosure via valueOf() function
  • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
  • FAQ: Frequently asked questions about CVE-2021-23566