Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Exposure of Sensitive Information to an Unauthorized Actor in nanoid #614

Closed
palisadoes opened this issue Mar 14, 2022 · 3 comments
Closed
Labels
bug Something isn't working good first issue Good for newcomers security Security fix

Comments

@palisadoes
Copy link
Contributor

Describe the bug

  • The earliest fixed version is 3.1.31.
  • This vulnerability may be due to a package or a dependency of this packages that we are not using. This needs to be considered

To Fix
image

Expected behavior
Version upgraded to 3.1.31

Actual behavior
Version under 3.1.31

Screenshots
image

Additional details

@palisadoes palisadoes added bug Something isn't working security Security fix labels Mar 14, 2022
@github-actions github-actions bot added the unapproved Unapproved for Pull Request label Mar 14, 2022
@palisadoes palisadoes added good first issue Good for newcomers and removed unapproved Unapproved for Pull Request labels Mar 14, 2022
@priyang12
Copy link

hi can i work on this issue?

@priyang12 priyang12 removed their assignment Mar 25, 2022
@rohit-raje-786
Copy link

@palisadoes there is no dependency name nanoid in the package.json file

@palisadoes
Copy link
Contributor Author

Thanks. It looks like it has been removed from the code base.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working good first issue Good for newcomers security Security fix
Projects
None yet
Development

No branches or pull requests

3 participants