nanoid (aka Nano ID) before 5.0.9 mishandles non-integer values. 3.3.8 is also a fixed version.
History

Fri, 14 Feb 2025 02:30:00 +0000

Type Values Removed Values Added
First Time appeared Redhat openshift Ai
Redhat rhdh
CPEs cpe:/a:redhat:openshift_ai:2.17::el8
cpe:/a:redhat:rhdh:1.4::el9
Vendors & Products Redhat openshift Ai
Redhat rhdh

Thu, 13 Feb 2025 00:45:00 +0000

Type Values Removed Values Added
First Time appeared Redhat
Redhat acm
Redhat ansible Automation Platform
Redhat discovery
Redhat logging
Redhat multicluster Engine
Redhat openshift
Redhat openshift Data Foundation
Redhat openshift Devspaces
Redhat service Mesh
CPEs cpe:/a:redhat:acm:2.11::el9
cpe:/a:redhat:acm:2.12::el9
cpe:/a:redhat:ansible_automation_platform:2.5::el8
cpe:/a:redhat:ansible_automation_platform:2.5::el9
cpe:/a:redhat:logging:5.9::el9
cpe:/a:redhat:multicluster_engine:2.6::el8
cpe:/a:redhat:multicluster_engine:2.6::el9
cpe:/a:redhat:multicluster_engine:2.7::el8
cpe:/a:redhat:multicluster_engine:2.7::el9
cpe:/a:redhat:openshift:4.17::el9
cpe:/a:redhat:openshift_data_foundation:4.16::el9
cpe:/a:redhat:openshift_data_foundation:4.17::el9
cpe:/a:redhat:openshift_devspaces:3::el9
cpe:/a:redhat:service_mesh:2.5::el8
cpe:/o:redhat:discovery:1.0::el9
Vendors & Products Redhat
Redhat acm
Redhat ansible Automation Platform
Redhat discovery
Redhat logging
Redhat multicluster Engine
Redhat openshift
Redhat openshift Data Foundation
Redhat openshift Devspaces
Redhat service Mesh

Thu, 12 Dec 2024 19:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Mon, 09 Dec 2024 14:15:00 +0000

Type Values Removed Values Added
Title nanoid: nanoid mishandles non-integer values
Weaknesses CWE-835
References
Metrics threat_severity

None

cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Mon, 09 Dec 2024 01:30:00 +0000

Type Values Removed Values Added
Description nanoid (aka Nano ID) before 5.0.9 mishandles non-integer values. 3.3.8 is also a fixed version.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-12-12T18:50:58.526Z

Reserved: 2024-12-09T00:00:00

Link: CVE-2024-55565

cve-icon Vulnrichment

Updated: 2024-12-12T18:50:48.702Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-12-09T02:15:19.607

Modified: 2024-12-12T19:15:13.670

Link: CVE-2024-55565

cve-icon Redhat

Severity : Moderate

Publid Date: 2024-12-09T00:00:00Z

Links: CVE-2024-55565 - Bugzilla