CVE-2021-23440

Related Vulnerabilities: CVE-2021-23440  

This affects the package set-value before 4.0.1. A type confusion vulnerability can lead to a bypass of CVE-2019-10747 when the user-provided keys used in the path parameter are arrays.

Description

The MITRE CVE dictionary describes this issue as:

This affects the package set-value before 4.0.1. A type confusion vulnerability can lead to a bypass of CVE-2019-10747 when the user-provided keys used in the path parameter are arrays.

Additional Information

  • Bugzilla 2004944: CVE-2021-23440 nodejs-set-value: type confusion allows bypass of CVE-2019-10747
  • CWE-843: Access of Resource Using Incompatible Type ('Type Confusion')
  • FAQ: Frequently asked questions about CVE-2021-23440