endpointlabs / VulnerableDotNetCore3Project

.Net Core 3.0
0 stars 0 forks source link

CVE-2021-23566 | nanoid:3.1.20 (CWE-200) #93

Closed ckalpakoglu closed 1 year ago

ckalpakoglu commented 1 year ago

Due Date: 2023-01-10

A medium severity vulnerability has been discovered in your project.

Project Name: kondukto-ui-vue

Scanner Name: dependabot

Cwe ID: 200

Cwe Name: Information Exposure

Cwe Link: https://cwe.mitre.org/data/definitions/200.html

File: package-lock.json

Packages:

References:

Kondukto Remediation 1: fgdfgdg 2: gbngf 3: kjnkj

Training(Secure Code Warrior):


Tool Description: ### Summary

Exposure of Sensitive Information to an Unauthorized Actor in nanoid

Fixed Patch

3.1.31

The package nanoid from 3.0.0, before 3.1.31, are vulnerable to Information Exposure via the valueOf() function which allows to reproduce the last id generated.

Kondukto Link: https://82.kondukto.local/projects/63b2e875fcd0c2a01b845757/vulns/appsec?page=1&perPage=15&id=in:63bbc8a5b3a8a9664878e70e Deeplink: https://github.com/advisories/GHSA-qrpm-p2h7-hrv2

ckalpakoglu commented 1 year ago

The issue has been closed by Kondukto since it is marked as won't fix.