Описание
The package nanoid from 3.0.0 and before 3.1.31 are vulnerable to Information Exposure via the valueOf() function which allows to reproduce the last id generated.
A flaw was found in the nanoid library where the valueOf() function allows the reproduction of the last id generated. This flaw allows an attacker to expose sensitive information.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Migration Toolkit for Virtualization | migration-toolkit-virtualization/mtv-ui-rhel8 | Fix deferred | ||
| OpenShift Developer Tools and Services | odo | Not affected | ||
| Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/console-rhel8 | Affected | ||
| Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/grc-ui-rhel8 | Affected | ||
| Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/kui-web-terminal-rhel8 | Affected | ||
| Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/search-ui-rhel8 | Affected | ||
| Red Hat Ansible Automation Platform 2 | automation-controller | Will not fix | ||
| Red Hat Data Grid 8 | org.infinispan-infinispan-console | Not affected | ||
| Red Hat JBoss Enterprise Application Platform 7 | io.smallrye-smallrye-open-api-parent | Not affected | ||
| Red Hat JBoss Enterprise Application Platform Expansion Pack | io.smallrye-smallrye-open-api-parent | Not affected |
Показывать по
Дополнительная информация
Статус:
5.5 Medium
CVSS3
Связанные уязвимости
The package nanoid from 3.0.0 and before 3.1.31 are vulnerable to Information Exposure via the valueOf() function which allows to reproduce the last id generated.
The package nanoid from 3.0.0 and before 3.1.31 are vulnerable to Information Exposure via the valueOf() function which allows to reproduce the last id generated.
The package nanoid from 3.0.0 and before 3.1.31 are vulnerable to Info ...
Exposure of Sensitive Information to an Unauthorized Actor in nanoid
Уязвимость функции valueOf() JavaScript-библиотеки для генерации уникальных строковых идентификаторов nanoid, позволяющая нарушителю раскрыть защищаемую информацию
5.5 Medium
CVSS3