QID 980582
QID 980582: Nodejs (npm) Security Update for jointjs (GHSA-f3pp-32qc-36w4)
This affects the package jointjs before 3.4.2. A type confusion vulnerability can lead to a bypass of CVE-2020-28480 when the user-provided keys used in the path parameter are arrays in the setByPath function.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-f3pp-32qc-36w4 for updates pertaining to this vulnerability.
Vendor References
- GHSA-f3pp-32qc-36w4 -
github.com/advisories/GHSA-f3pp-32qc-36w4
CVEs related to QID 980582
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-f3pp-32qc-36w4 | jointjs |
|