Vulnerabilities > CVE-2021-23807 - Type Confusion vulnerability in Janl Jsonpointer
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
HIGH Integrity impact
HIGH Availability impact
HIGH Summary
This affects the package jsonpointer before 5.0.0. A type confusion vulnerability can lead to a bypass of a previous Prototype Pollution fix when the pointer components are arrays.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 10 |
Common Weakness Enumeration (CWE)
References
- https://github.com/janl/node-jsonpointer/commit/a0345f3550cd9c4d89f33b126390202b89510ad4
- https://github.com/janl/node-jsonpointer/commit/a0345f3550cd9c4d89f33b126390202b89510ad4
- https://github.com/janl/node-jsonpointer/pull/51
- https://github.com/janl/node-jsonpointer/pull/51
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1910273
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1910273
- https://snyk.io/vuln/SNYK-JS-JSONPOINTER-1577288
- https://snyk.io/vuln/SNYK-JS-JSONPOINTER-1577288