First published: Mon Dec 09 2024(Updated: )
nanoid (aka Nano ID) before 5.0.9 mishandles non-integer values. 3.3.8 is also a fixed version.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
npm/nanoid | <3.3.8 | 3.3.8 |
npm/nanoid | >=4.0.0<5.0.9 | 5.0.9 |
IBM Rational Team Concert | <=1.0.0-1.0.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-55565 is classified as a moderate vulnerability due to its potential impact on application behavior when mishandling non-integer values.
To fix CVE-2024-55565, upgrade nanoid to version 5.0.9 or later or to version 3.3.8, which addresses the vulnerability.
CVE-2024-55565 affects all versions of nanoid prior to 5.0.9 and specifically versions before 3.3.8.
CVE-2024-55565 can lead to unpredictable behavior when fractional values are used with the nanoid library.
If you're using nanoid version prior to 5.0.9 or 3.3.8, you are likely using a vulnerable version susceptible to CVE-2024-55565.