Fedora Account System
Red Hat Associate
Red Hat Customer
The package nanoid from 3.0.0 and before 3.1.31 are vulnerable to Information Exposure via the valueOf() function which allows to reproduce the last id generated. References: https://github.com/advisories/GHSA-qrpm-p2h7-hrv2 https://snyk.io/vuln/SNYK-JS-NANOID-2332193 Upstream PR: https://github.com/ai/nanoid/pull/328 Upstream commit: https://github.com/ai/nanoid/commit/2b7bd9332bc49b6330c7ddb08e5c661833db2575
This issue has been addressed in the following products: Red Hat Advanced Cluster Management for Kubernetes 2.3 for RHEL 7 Red Hat Advanced Cluster Management for Kubernetes 2.3 for RHEL 8 Via RHSA-2022:0595 https://access.redhat.com/errata/RHSA-2022:0595
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2021-23566
Created golang-ariga-atlas tracking bugs for this issue: Affects: fedora-all [bug 2069293] Created golang-vitess tracking bugs for this issue: Affects: fedora-all [bug 2069288] Created pcs tracking bugs for this issue: Affects: fedora-all [bug 2069289] Created python-ipyparallel tracking bugs for this issue: Affects: fedora-all [bug 2069290] Created vagrant tracking bugs for this issue: Affects: fedora-all [bug 2069291] Created zuul tracking bugs for this issue: Affects: fedora-all [bug 2069292]
This issue has been addressed in the following products: Red Hat Advanced Cluster Management for Kubernetes 2.3 for RHEL 7 Red Hat Advanced Cluster Management for Kubernetes 2.3 for RHEL 8 Via RHSA-2022:1083 https://access.redhat.com/errata/RHSA-2022:1083
This issue has been addressed in the following products: Red Hat Advanced Cluster Management for Kubernetes 2.4 for RHEL 8 Via RHSA-2022:1476 https://access.redhat.com/errata/RHSA-2022:1476
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.11 Via RHSA-2022:5069 https://access.redhat.com/errata/RHSA-2022:5069
This issue has been addressed in the following products: Red Hat OpenShift Data Foundation 4.11 on RHEL8 Via RHSA-2022:6156 https://access.redhat.com/errata/RHSA-2022:6156