Description
This affects the package jsonpointer before 5.0.0. A type confusion vulnerability can lead to a bypass of a previous Prototype Pollution fix when the pointer components are arrays.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-2277 | Prototype Pollution in node-jsonpointer |
Github GHSA |
GHSA-282f-qqgm-c34q | Prototype Pollution in node-jsonpointer |
References
History
Wed, 05 Mar 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Janl
Janl jsonpointer |
|
| CPEs | cpe:2.3:a:janl:jsonpointer:*:*:*:*:*:node.js:*:* | |
| Vendors & Products |
Jsonpointer Project
Jsonpointer Project jsonpointer |
Janl
Janl jsonpointer |
Status: PUBLISHED
Assigner: snyk
Published:
Updated: 2024-09-16T23:25:55.568Z
Reserved: 2021-01-08T00:00:00.000Z
Link: CVE-2021-23807
No data.
Status : Modified
Published: 2021-11-03T18:15:08.230
Modified: 2025-03-05T16:24:40.203
Link: CVE-2021-23807
OpenCVE Enrichment
No data.
EUVD
Github GHSA