Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-55565

Опубликовано: 09 дек. 2024
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

nanoid (aka Nano ID) before 5.0.9 mishandles non-integer values. 3.3.8 is also a fixed version.

A flaw was found in nanoid. Affected versions of nanoid mishandles non-integer values. When nanoid is called with a fractional value, there were a number of undesirable effects:

  • In browser and non-secure, the code infinite loops on while (size--)
  • In node, the value of poolOffset becomes fractional, causing calls to nanoid to return zeroes until the pool is next filled: when i is initialized to poolOffset, pool[i] & 63 -> undefined & 63 -> 0
  • If the first call in node is a fractional argument, the initial buffer allocation fails with an error The highest impact of this issue system availability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Cryostat 3io.cryostat-cryostat3Fix deferred
Migration Toolkit for Applications 7mta/mta-cli-rhel9Fix deferred
Migration Toolkit for Applications 7mta/mta-ui-rhel9Fix deferred
Migration Toolkit for Containersrhmtc/openshift-migration-ui-rhel8Fix deferred
Migration Toolkit for Virtualizationmigration-toolkit-virtualization/mtv-console-plugin-rhel9Fix deferred
Node HealthCheck Operatorworkload-availability/node-remediation-console-rhel8Will not fix
OpenShift Lightspeedopenshift-lightspeed-tech-preview/lightspeed-console-plugin-rhel9Affected
OpenShift Pipelinesopenshift-pipelines/pipelines-console-plugin-rhel8Will not fix
OpenShift Pipelinesopenshift-pipelines/pipelines-hub-api-rhel8Will not fix
OpenShift Pipelinesopenshift-pipelines/pipelines-hub-db-migration-rhel8Will not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-835
https://bugzilla.redhat.com/show_bug.cgi?id=2331063nanoid: nanoid mishandles non-integer values

EPSS

Процентиль: 49%
0.00679
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.3
ubuntu
больше 1 года назад

nanoid (aka Nano ID) before 5.0.9 mishandles non-integer values. 3.3.8 is also a fixed version.

CVSS3: 4.3
nvd
больше 1 года назад

nanoid (aka Nano ID) before 5.0.9 mishandles non-integer values. 3.3.8 is also a fixed version.

CVSS3: 4.3
debian
больше 1 года назад

nanoid (aka Nano ID) before 5.0.9 mishandles non-integer values. 3.3.8 ...

CVSS3: 4.3
github
больше 1 года назад

Predictable results in nanoid generation when given non-integer values

EPSS

Процентиль: 49%
0.00679
Низкий

6.5 Medium

CVSS3