QID 982983
QID 982983: Nodejs (npm) Security Update for jointjs (GHSA-qwp9-52h8-xgg8)
The package jointjs before 3.3.0 are vulnerable to Prototype Pollution via util.setByPath (https://resources.jointjs.com/docs/jointjs/v3.2/joint.htmlutil.setByPath). The path used the access the object's key and set the value is not properly sanitized, leading to a Prototype Pollution.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-qwp9-52h8-xgg8 for updates pertaining to this vulnerability.
Vendor References
- GHSA-qwp9-52h8-xgg8 -
github.com/advisories/GHSA-qwp9-52h8-xgg8
CVEs related to QID 982983
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-qwp9-52h8-xgg8 | jointjs |
|