GHSA-cq8r-fc3q-6hg2

Suggest an improvement
Source
https://github.com/advisories/GHSA-cq8r-fc3q-6hg2
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/04/GHSA-cq8r-fc3q-6hg2/GHSA-cq8r-fc3q-6hg2.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-cq8r-fc3q-6hg2
Aliases
Published
2021-04-13T15:29:40Z
Modified
2024-11-14T01:42:21.552570Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
Denial of Service (DoS) via the unsetByPath function in jsjoints
Details

The package jointjs before 3.3.0 are vulnerable to Denial of Service (DoS) via the unsetByPath function.

Database specific
{
    "nvd_published_at": "2021-01-19T15:15:00Z",
    "github_reviewed_at": "2021-04-06T20:51:59Z",
    "severity": "HIGH",
    "github_reviewed": true,
    "cwe_ids": [
        "CWE-400"
    ]
}
References

Affected packages

npm / jointjs

Package

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.3.0