Junglewise Threat Intelligence

CVE-2021-23566: nanoid information exposure via valueOf

CVE-2021-23566 · Severity: low · CVSS 3.1 · Published 2022-01-21

Technologies: Ai Nanoid. Vendors: npm.

Executive brief

nanoid is a popular JavaScript library used to generate unique identifiers (IDs) for database records and other applications. A vulnerability in versions 3.0.0 through 3.1.30 allows an attacker with local access to recover previously generated IDs by exploiting the valueOf() function, potentially compromising the uniqueness guarantee that applications rely on for security or data integrity.

Technical details

The vulnerability is an information exposure flaw (CWE-200, CWE-704) in nanoid's valueOf() function implementation. Versions 3.0.0 through 3.1.30 allow an attacker to reproduce the last generated ID, breaking the confidentiality of ID generation. This is a local privilege vulnerability requiring local access (AV:L) and low privileges (PR:L), with no user interaction needed. An attacker can deterministically recreate previously issued IDs, which may compromise applications using nanoid for security tokens, session identifiers, or other confidential purposes. The vulnerability was fixed in version 3.1.31 via commit 2b7bd9332bc49b6330c7ddb08e5c661833db2575.

Affected products

  • ai nanoid 3.0.0 to 3.1.30

Timeline

  • 2022-01-21: disclosed: Advisory published via GitHub Security Advisory GHSA-qrpm-p2h7-hrv2
  • 2022-01-11: patched: Fix merged in pull request #328, available in version 3.1.31

References