Vulnerabilities > CVE-2021-23807 - Type Confusion vulnerability in Jsonpointer Project Jsonpointer
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
HIGH Integrity impact
HIGH Availability impact
HIGH Summary
This affects the package jsonpointer before 5.0.0. A type confusion vulnerability can lead to a bypass of a previous Prototype Pollution fix when the pointer components are arrays.
Vulnerable Configurations
Common Weakness Enumeration (CWE)
References
- https://github.com/janl/node-jsonpointer/commit/a0345f3550cd9c4d89f33b126390202b89510ad4
- https://github.com/janl/node-jsonpointer/commit/a0345f3550cd9c4d89f33b126390202b89510ad4
- https://github.com/janl/node-jsonpointer/pull/51
- https://github.com/janl/node-jsonpointer/pull/51
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1910273
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1910273
- https://snyk.io/vuln/SNYK-JS-JSONPOINTER-1577288
- https://snyk.io/vuln/SNYK-JS-JSONPOINTER-1577288