Description
This affects the package immer before 9.0.6. A type confusion vulnerability can lead to a bypass of CVE-2020-28477 when the user-provided keys used in the path parameter are arrays.
Recommendation
Update the immer package to the latest compatible version. Followings are version details:
- Affected version(s): >= 7.0.0, < 9.0.6
- Patched version(s): 9.0.6
References
Related Issues
- Prototype Pollution in immer - immer - GHSA-c36v-fmgq-m8hx - CVE-2021-3757
- jquery-plugin-query-object contains prototype pollution vulnerability - CVE-2021-20083
- merge vulnerable to Prototype Pollution - CVE-2021-3645
- Prototype Pollution in merge-change - CVE-2021-23421
You might also like:
- Tags:
- npm
- immer
Anything's wrong? Let us know Last updated on April 30, 2024


