HIGH7.5
GHSA-cq8r-fc3q-6hg2
Denial of Service (DoS) via the unsetByPath function in jsjoints
Quick fix
GHSA-cq8r-fc3q-6hg2 — jointjs: upgrade to the fixed version with the command below.
npm install jointjs@3.3.0Details
The package jointjs before 3.3.0 are vulnerable to Denial of Service (DoS) via the unsetByPath function.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2020-28479[ADVISORY]
- https://github.com/clientIO/joint/commit/ec7ab01b512a3c06a9944a25d50f255bf07c3499[WEB]
- https://github.com/clientIO/joint/releases/tag/v3.3.0[WEB]
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-1062040[WEB]
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1062039[WEB]
- https://snyk.io/vuln/SNYK-JS-JOINTJS-1062038[WEB]