UBUNTU-CVE-2021-23440
Dashboard / Vulnerabilities / UBUNTU-CVE-2021-23440
Summary:
Details: This affects the package set-value before <2.0.1, >=3.0.0 <4.0.1. A type confusion vulnerability can lead to a bypass of CVE-2019-10747 when the user-provided keys used in the path parameter are arrays.
References: https://ubuntu.com/security/CVE-2021-23440, https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1584212, https://github.com/jonschlinkert/set-value/commit/7cf8073bb06bf0c15e08475f9f952823b4576452, https://www.huntr.dev/bounties/2eae1159-01de-4f82-a177-7478a408c4a2/, https://snyk.io/vuln/SNYK-JS-SETVALUE-1540541, https://github.com/jonschlinkert/set-value/pull/33, https://www.cve.org/CVERecord?id=CVE-2021-23440
Affected packages
Package
Name: node-set-value
Purl: pkg:deb/ubuntu/node-set-value?arch=source&distro=bionic
Affected ranges
Type: ECOSYSTEM
Events:
