Description
nanoid (aka Nano ID) before 5.0.9 mishandles non-integer values. 3.3.8 is also a fixed version.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:NExploitability: 2.8 | Impact: 1.4Attack Vector: Network
Complexity: Low
Privileges: Low
User Interaction: None
Scope: Unchanged
Confidentiality: None
Integrity: Low
Availability: None
Affected Packages3 packages
🔴Vulnerability Details
3OSVCVE-2024-55565: nanoid (aka Nano ID) before 5↗2024-12-09 ▶ OSVPredictable results in nanoid generation when given non-integer values↗2024-12-09 ▶ GHSAPredictable results in nanoid generation when given non-integer values↗2024-12-09 ▶ 📋Vendor Advisories
2Red Hatnanoid: nanoid mishandles non-integer values↗2024-12-09 ▶ DebianCVE-2024-55565: node-mocha - nanoid (aka Nano ID) before 5.0.9 mishandles non-integer values. 3.3.8 is also a...↗2024 ▶