PT-2023-32980 · Cuid+1 · Cuid+2

Publicado

2023-06-12

·

Atualizado

2023-06-12

Nenhuma

Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
Name of the Vulnerable Software and Affected Versions @keystone-6/* versions (affected versions not specified)
Description The cuid package is deprecated and marked as insecure by its author due to security concerns. It is recommended to use @paralleldrive/cuid2 instead. The issue affects @keystone-6/* and its upstream dependencies. There have been no reported real-world incidents of this issue being exploited.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

GHSA-5FP6-4XW3-XQQ3

Produtos afetados

@Keystone-6
@Paralleldrive/Cuid2
Cuid