9.8
CVSSv3

CVE-2021-23436

Published: 01/09/2021 Updated: 10/09/2021
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

This affects the package immer prior to 9.0.6. A type confusion vulnerability can lead to a bypass of CVE-2020-28477 when the user-provided keys used in the path parameter are arrays. In particular, this bypass is possible because the condition (p === "__proto__" || p === "constructor") in applyPatches_ returns false if p is ['__proto__'] (or ['constructor']). The === operator (strict equality operator) returns false if the operands have different type.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

immer project immer

Vendor Advisories

Synopsis Important: Red Hat Process Automation Manager 7131 security update Type/Severity Security Advisory: Important Topic An update is now available for Red Hat Process Automation ManagerRed Hat Product Security has rated this update as having a security impact of Low A Common Vulnerability Scoring System (CVSS) base score, which gives ...

Github Repositories

Tool for validating Grafana community plugins

Grafana Plugin Validator This tool helps speed up the process of publishing plugins to Grafanacom It runs a series of analyzers to ensure plugins are following best practices, checking for security and structural issues, as well as specific requirements related to publishing A general overview of these requirements can be found here: grafanacom/docs/grafana/lates

EVER Wallet browser extension

EVER Wallet A browser extension to manage Everscale wallets and access dApps directly from your browser How to build # Prepare builder container docker build --tag ever-wallet-extension # Build extension docker run -ti --rm --mount type=bind,source=$(pwd),target=/app ever-wallet-extension # Extens

Khulnasoft Plugin Validator This tool helps speed up the process of publishing plugins to Khulnasoftcom It runs a series of analyzers to ensure plugins are following best practices, checking for security and structural issues, as well as specific requirements related to publishing A general overview of these requirements can be found here: grafanacom/docs/grafana