First published: Wed Nov 03 2021(Updated: )
This affects all versions of package json-pointer. A type confusion vulnerability can lead to a bypass of CVE-2020-7709 when the pointer components are arrays.
Credit: report@snyk.io
Affected Software | Affected Version | How to fix |
---|---|---|
jsonpointer | ||
Manuelstofer Json-pointer | <0.6.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this issue is CVE-2021-23820.
The severity of CVE-2021-23820 is critical with a CVSS score of 9.8.
All versions of the json-pointer package are affected by CVE-2021-23820.
CVE-2021-23820 can lead to a bypass of CVE-2020-7709 when the pointer components are arrays.
Yes, you can find the references for CVE-2021-23820 [here](https://access.redhat.com/security/cve/CVE-2020-7709), [here](https://snyk.io/vuln/SNYK-JS-JSONPOINTER-1577287), and [here](https://github.com/manuelstofer/json-pointer/blob/master/index.js#23L78).