CVE-2021-23566

MEDIUM5.5EPSS 0.03%

Exposure of Sensitive Information to an Unauthorized Actor in nanoid

Published: 1/21/2022Modified: 11/4/2025
Also known as:GHSA-qrpm-p2h7-hrv2DEBIAN-CVE-2021-23566

Description

The package nanoid from 3.0.0, before 3.1.31, are vulnerable to Information Exposure via the valueOf() function which allows to reproduce the last id generated.

Affected packages (5)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM5.5CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

References (10)