Information disclosure in nanoid - CVE-2021-23566

 

Information disclosure in nanoid - CVE-2021-23566

Published: January 19, 2022


Vulnerability identifier: #VU59833
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-23566
CWE-ID: CWE-200
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local attacker to gain access to potentially sensitive information.

The vulnerability exists due to excessive data output by the application in the valueOf() function. A local attacker can gain unauthorized access to sensitive information on the system.


Affected software

nanoid
Cloud Pak for Security (CP4S)
IBM Watson Machine Learning Accelerator
Business Automation Insights
Storage Ceph
Red Hat Advanced Cluster Management for Kubernetes
IBM Cloud Pak for Business Automation
IBM Security QRadar Analyst Workflow
IBM QRadar Use Case Manager
OpenShift Data Foundation (formerly OpenShift Container Storage)
Red Hat OpenShift Container Platform

How to mitigate CVE-2021-23566

Install updates from vendor's website.

nanoid - update to 3.1.31
Cloud Pak for Security (CP4S) - update to 1.10.7.0
IBM Watson Machine Learning Accelerator - update to 2.3.4
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.3.6, 2.3.8, 2.4.3
Business Automation Insights - addressed in versions 24.0.0.0.5, 24.0.1.0.5, 25.0.0.0.2
IBM Cloud Pak for Business Automation - addressed in versions 24.0.1-IF006, 25.0.0-IF003
IBM Security QRadar Analyst Workflow - update to 2.31.4
IBM QRadar Use Case Manager - update to 3.5.0
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.11.0
Red Hat OpenShift Container Platform - update to 4.11.0
Storage Ceph - update to 7.1

External References

Related Security Bulletins