Information disclosure in nanoid - CVE-2021-23566
Published: January 19, 2022
Vulnerability identifier: #VU59833
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-23566
CWE-ID: CWE-200
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local attacker to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output by the application in the valueOf() function. A local attacker can gain unauthorized access to sensitive information on the system.
Affected software
nanoid
Cloud Pak for Security (CP4S)
IBM Watson Machine Learning Accelerator
Business Automation Insights
Storage Ceph
Red Hat Advanced Cluster Management for Kubernetes
IBM Cloud Pak for Business Automation
IBM Security QRadar Analyst Workflow
IBM QRadar Use Case Manager
OpenShift Data Foundation (formerly OpenShift Container Storage)
Red Hat OpenShift Container Platform
Cloud Pak for Security (CP4S)
IBM Watson Machine Learning Accelerator
Business Automation Insights
Storage Ceph
Red Hat Advanced Cluster Management for Kubernetes
IBM Cloud Pak for Business Automation
IBM Security QRadar Analyst Workflow
IBM QRadar Use Case Manager
OpenShift Data Foundation (formerly OpenShift Container Storage)
Red Hat OpenShift Container Platform
How to mitigate CVE-2021-23566
Install updates from vendor's website.
nanoid - update to 3.1.31
Cloud Pak for Security (CP4S) - update to 1.10.7.0
IBM Watson Machine Learning Accelerator - update to 2.3.4
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.3.6, 2.3.8, 2.4.3
Business Automation Insights - addressed in versions 24.0.0.0.5, 24.0.1.0.5, 25.0.0.0.2
IBM Cloud Pak for Business Automation - addressed in versions 24.0.1-IF006, 25.0.0-IF003
IBM Security QRadar Analyst Workflow - update to 2.31.4
IBM QRadar Use Case Manager - update to 3.5.0
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.11.0
Red Hat OpenShift Container Platform - update to 4.11.0
Storage Ceph - update to 7.1
Cloud Pak for Security (CP4S) - update to 1.10.7.0
IBM Watson Machine Learning Accelerator - update to 2.3.4
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.3.6, 2.3.8, 2.4.3
Business Automation Insights - addressed in versions 24.0.0.0.5, 24.0.1.0.5, 25.0.0.0.2
IBM Cloud Pak for Business Automation - addressed in versions 24.0.1-IF006, 25.0.0-IF003
IBM Security QRadar Analyst Workflow - update to 2.31.4
IBM QRadar Use Case Manager - update to 3.5.0
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.11.0
Red Hat OpenShift Container Platform - update to 4.11.0
Storage Ceph - update to 7.1
External References
Related Security Bulletins
- Information disclosure in Nanoid
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.3
- Information disclosure in IBM QRadar Use Case Manager
- Multiple vulnerabilities in Red Hat OpenShift Data Foundation
- Multiple vulnerabilities in OpenShift Container Platform 4.11
- Multiple vulnerabilities in IBM Cloud Pak for Security (CP4S)
- Multiple vulnerabilities in Watson Machine Learning Accelerator on Cloud Pak for Data
- Information disclosure in IBM Storage Ceph
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.3
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.4
- Multiple vulnerabilities in IBM Analyst Workflow
- Multiple vulnerabilities in IBM Business Automation Insights
- Multiple vulnerabilities in IBM Cloud Pak for Business Automation