nano-id is a unique string ID generator for Rust. Affected versions of the nano-id crate incorrectly generated IDs using a reduced character set in the `nano_id::base62` and `nano_id::base58` functions. Specifically, the `base62` function used a character set of 32 symbols instead of the intended 62 symbols, and the `base58` function used a character set of 16 symbols instead of the intended 58 symbols. Additionally, the `nano_id::gen` macro is also affected when a custom character set that is not a power of 2 in size is specified. It should be noted that `nano_id::base64` is not affected by this vulnerability. This can result in a significant reduction in entropy, making the generated IDs predictable and vulnerable to brute-force attacks when the IDs are used in security-sensitive contexts such as session tokens or unique identifiers. The vulnerability is fixed in 0.4.0.
The `nano_id::base62` function used a character set of 32 characters instead of the required 62, and the `nano_id::base58` function used 16 characters instead of 58. The `nano_id::gen` macro was additionally vulnerable when using a custom character set whose size is not a power of 2. The consequence is a significant reduction in the space of possible identifier values, making them predictable. The `nano_id::base64` function is not affected by this issue.
An attacker can predict or brute-force guess generated identifiers in a short time, which in case of using them as session tokens or unique keys poses a risk of unauthorized access to accounts or resources (violation of confidentiality and integrity).
Update the nano-id library to version 0.4.0 or later, in which the vulnerability has been fixed. After the update, it is recommended to invalidate and regenerate all security identifiers (session tokens, unique keys) produced by vulnerable versions of the library.
The nano-id library for Rust (crate nano-id) — versions prior to 0.4.0, using the `nano_id::base62` function, `nano_id::base58` function, or the `nano_id::gen` macro with a custom character set whose size is not a power of 2
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:LViz Nano Id
APPViz< 0.4.0