Description
This affects the package jointjs before 3.4.2. A type confusion vulnerability can lead to a bypass of CVE-2020-28480 when the user-provided keys used in the path parameter are arrays in the setByPath function.
Remediation
References
https://github.com/clientIO/joint/commit/e5bf89efef6d5ea572d66870ffd86560de7830a8
https://github.com/clientIO/joint/pull/1514
https://github.com/clientIO/joint/releases/tag/v3.4.2
https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-1655817
https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1655816
https://snyk.io/vuln/SNYK-JS-JOINTJS-1579578
Related Vulnerabilities
CVE-2023-37946 Vulnerability in maven package org.openshift.jenkins:openshift-login
CVE-2012-3451 Vulnerability in maven package org.apache.cxf:cxf-bundle-minimal
CVE-2023-4759 Vulnerability in maven package org.eclipse.jgit:org.eclipse.jgit
CVE-2010-1330 Vulnerability in maven package org.jruby:jruby
CVE-2021-21290 Vulnerability in maven package io.netty:netty-testsuite