Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVE-2021-23566 | nanoid:3.1.20 (CWE-200) #93

Closed
ckalpakoglu opened this issue Jan 9, 2023 · 1 comment
Closed

CVE-2021-23566 | nanoid:3.1.20 (CWE-200) #93

ckalpakoglu opened this issue Jan 9, 2023 · 1 comment
Assignees
Labels
bug Something isn't working KONDUKTO wontfix This will not be worked on

Comments

@ckalpakoglu
Copy link

Due Date: 2023-01-10

A medium severity vulnerability has been discovered in your project.

Project Name: kondukto-ui-vue

Scanner Name: dependabot

Cwe ID: 200

Cwe Name: Information Exposure

Cwe Link: https://cwe.mitre.org/data/definitions/200.html

File: package-lock.json

Packages:

  • nanoid:3.1.20

References:

Kondukto Remediation 1: fgdfgdg 2: gbngf 3: kjnkj

Training(Secure Code Warrior):





Tool Description: ### Summary

Exposure of Sensitive Information to an Unauthorized Actor in nanoid

Fixed Patch

3.1.31

The package nanoid from 3.0.0, before 3.1.31, are vulnerable to Information Exposure via the valueOf() function which allows to reproduce the last id generated.

Kondukto Link: https://82.kondukto.local/projects/63b2e875fcd0c2a01b845757/vulns/appsec?page=1&perPage=15&id=in:63bbc8a5b3a8a9664878e70e
Deeplink: GHSA-qrpm-p2h7-hrv2

@ckalpakoglu ckalpakoglu added bug Something isn't working KONDUKTO labels Jan 9, 2023
@ckalpakoglu ckalpakoglu self-assigned this Jan 9, 2023
@ckalpakoglu ckalpakoglu added the wontfix This will not be worked on label Feb 14, 2023
@ckalpakoglu
Copy link
Author

The issue has been closed by Kondukto since it is marked as won't fix.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working KONDUKTO wontfix This will not be worked on
Projects
None yet
Development

No branches or pull requests

1 participant