Description
This affects the package dotty before 0.1.2. A type confusion vulnerability can lead to a bypass of CVE-2021-25912 when the user-provided keys used in the path parameter are arrays.
Recommendation
Update the dotty package to the latest compatible version. Followings are version details:
- Affected version(s): < 0.1.2
- Patched version(s): 0.1.2
References
Related Issues
- Prototype pollution in dotty - CVE-2021-25912
- Prototype Pollution in record-like-deep-assign - CVE-2021-23402
- Prototype Pollution in ts-nodash - CVE-2021-23403
- Prototype Pollution in async - CVE-2021-43138
You might also like:
- Tags:
- npm
- dotty
Anything's wrong? Let us know Last updated on February 01, 2023


