Description


This affects the package set-value before <2.0.1, >=3.0.0 <4.0.1. A type confusion vulnerability can lead to a bypass of CVE-2019-10747 when the user-provided keys used in the path parameter are arrays.

Related CPE's


a

set-value_project

set-value

2

Weaknesses



CWE-843

CVSS impact metrics


CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

7.3 · High

Information


Source identifier

[email protected]

Vulnerability status

Modified

Published

2021-09-12T11:15:07.383Z

4 years ago

Last modified

2024-11-21T04:51:45.840Z

1 year ago