5.3
CVSSv3

CVE-2021-23413

Published: 25/07/2021 Updated: 27/08/2021
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 5.3 | Impact Score: 1.4 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

This affects the package jszip prior to 3.7.0. Crafting a new zip file with filenames set to Object prototype values (e.g __proto__, toString, etc) results in a returned object with a modified prototype instance.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

jszip project jszip