Описание
Prototype Pollution in dotty
This affects the package dotty before 0.1.2. A type confusion vulnerability can lead to a bypass of CVE-2021-25912 when the user-provided keys used in the path parameter are arrays.
Пакеты
Наименование
dotty
npm
Затронутые версииВерсия исправления
< 0.1.2
0.1.2
Связанные уязвимости
CVSS3: 5.6
nvd
больше 4 лет назад
This affects the package dotty before 0.1.2. A type confusion vulnerability can lead to a bypass of CVE-2021-25912 when the user-provided keys used in the path parameter are arrays.