QID 980207
QID 980207: Nodejs (npm) Security Update for dotty (GHSA-6g47-63mv-qpgh)
This affects the package dotty before 0.1.2. A type confusion vulnerability can lead to a bypass of CVE-2021-25912 when the user-provided keys used in the path parameter are arrays.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-6g47-63mv-qpgh for updates pertaining to this vulnerability.
Vendor References
- GHSA-6g47-63mv-qpgh -
github.com/advisories/GHSA-6g47-63mv-qpgh
CVEs related to QID 980207
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-6g47-63mv-qpgh | dotty |
|