CRITICAL9.8
GHSA-p3hc-fv2j-rp68
Prototype Pollution in swiper
Quick fix
GHSA-p3hc-fv2j-rp68 — swiper: upgrade to the fixed version with the command below.
npm install swiper@6.5.1Details
Versions of the package swiper before 6.5.1 are susceptible to prototype pollution.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2021-23370[ADVISORY]
- https://github.com/nolimits4web/Swiper/commit/ec358deab79a8cd2529465f07a0ead5dbcc264ad[WEB]
- https://github.com/nolimits4web/swiper/commit/9dad2739b7474f383474773d5ab898a0c29ac178[WEB]
- https://github.com/nolimits4web/swiper/blob/master/CHANGELOG.md#651-2021-03-29[WEB]
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARS-1244698[WEB]
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-1244699[WEB]
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWERGITHUBNOLIMITS4WEB-1244697[WEB]
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1244696[WEB]
- https://snyk.io/vuln/SNYK-JS-SWIPER-1088062[WEB]