The package nanoid from 3.0.0 and before 3.1.31 are vulnerable to Information Exposure via the valueOf() function which allows to reproduce the last id generated. References: https://github.com/advisories/GHSA-qrpm-p2h7-hrv2 https://snyk.io/vuln/SNYK-JS-NANOID-2332193 Upstream PR: https://github.com/ai/nanoid/pull/328 Upstream commit: https://github.com/ai/nanoid/commit/2b7bd9332bc49b6330c7ddb08e5c661833db2575
This issue has been addressed in the following products: Red Hat Advanced Cluster Management for Kubernetes 2.3 for RHEL 7 Red Hat Advanced Cluster Management for Kubernetes 2.3 for RHEL 8 Via RHSA-2022:0595 https://access.redhat.com/errata/RHSA-2022:0595
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2021-23566
Created golang-ariga-atlas tracking bugs for this issue: Affects: fedora-all [bug 2069293] Created golang-vitess tracking bugs for this issue: Affects: fedora-all [bug 2069288] Created pcs tracking bugs for this issue: Affects: fedora-all [bug 2069289] Created python-ipyparallel tracking bugs for this issue: Affects: fedora-all [bug 2069290] Created vagrant tracking bugs for this issue: Affects: fedora-all [bug 2069291] Created zuul tracking bugs for this issue: Affects: fedora-all [bug 2069292]
This issue has been addressed in the following products: Red Hat Advanced Cluster Management for Kubernetes 2.3 for RHEL 7 Red Hat Advanced Cluster Management for Kubernetes 2.3 for RHEL 8 Via RHSA-2022:1083 https://access.redhat.com/errata/RHSA-2022:1083
This issue has been addressed in the following products: Red Hat Advanced Cluster Management for Kubernetes 2.4 for RHEL 8 Via RHSA-2022:1476 https://access.redhat.com/errata/RHSA-2022:1476
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.11 Via RHSA-2022:5069 https://access.redhat.com/errata/RHSA-2022:5069
This issue has been addressed in the following products: Red Hat OpenShift Data Foundation 4.11 on RHEL8 Via RHSA-2022:6156 https://access.redhat.com/errata/RHSA-2022:6156