This affects the package dotty before 0.1.2. A type confusion vulnerability can lead to a bypass of CVE-2021-25912 when the user-provided keys used in the path parameter are arrays.
{
"unresolved_ranges": [
{
"cpes": [
"cpe:2.3:a:dotty_project:dotty:*:*:*:*:*:*:*:*"
],
"source": "CPE_RANGE",
"vendor_product": "dotty_project:dotty",
"extracted_events": [
{
"fixed": "0.1.2"
}
]
},
{
"source": "DESCRIPTION",
"extracted_events": [
{
"fixed": "0.1.2"
}
]
}
]
}