Exposure of Sensitive Information to an Unauthorized Actor in nanoid
Moderate severity
GitHub Reviewed
Published
Jan 21, 2022
to the GitHub Advisory Database
•
Updated Jan 27, 2023
Description
Published by the National Vulnerability Database
Jan 14, 2022
Reviewed
Jan 18, 2022
Published to the GitHub Advisory Database
Jan 21, 2022
Last updated
Jan 27, 2023
The package nanoid from 3.0.0, before 3.1.31, are vulnerable to Information Exposure via the valueOf() function which allows to reproduce the last id generated.
References