Description
This affects the package jointjs before 3.4.2. A type confusion vulnerability can lead to a bypass of CVE-2020-28480 when the user-provided keys used in the path parameter are arrays in the setByPath function.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-2047 | This affects the package jointjs before 3.4.2. A type confusion vulnerability can lead to a bypass of CVE-2020-28480 when the user-provided keys used in the path parameter are arrays in the setByPath function. |
Github GHSA |
GHSA-f3pp-32qc-36w4 | Prototype Pollution in jointjs |
References
History
No history.
Status: PUBLISHED
Assigner: snyk
Published:
Updated: 2024-09-16T20:58:36.745Z
Reserved: 2021-01-08T00:00:00.000Z
Link: CVE-2021-23444
No data.
Status : Modified
Published: 2021-09-21T17:15:09.390
Modified: 2024-11-21T05:51:46.200
Link: CVE-2021-23444
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA