VDB
Sign up
MEDIUM5.6

GHSA-f3pp-32qc-36w4

Prototype Pollution in jointjs

Quick fix

GHSA-f3pp-32qc-36w4 — jointjs: upgrade to the fixed version with the command below.

npm install jointjs@3.4.2

Details

This affects the package jointjs before 3.4.2. A type confusion vulnerability can lead to a bypass of CVE-2020-28480 when the user-provided keys used in the path parameter are arrays in the setByPath function.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/jointjs
Introduced in: 0Fixed in: 3.4.2
Fixnpm install jointjs@3.4.2

References