Medium severity5.6NVD Advisory· Published Sep 21, 2021· Updated Jun 17, 2026
CVE-2021-23444
CVE-2021-23444
Description
This affects the package jointjs before 3.4.2. A type confusion vulnerability can lead to a bypass of CVE-2020-28480 when the user-provided keys used in the path parameter are arrays in the setByPath function.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
jointjsnpm | < 3.4.2 | 3.4.2 |
Affected products
3- jointjs/jointjsdescription
Patches
Vulnerability mechanics
References
7- github.com/clientIO/joint/commit/e5bf89efef6d5ea572d66870ffd86560de7830a8nvdPatchThird Party AdvisoryWEB
- snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-1655817nvdExploitThird Party AdvisoryWEB
- snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1655816nvdExploitThird Party AdvisoryWEB
- snyk.io/vuln/SNYK-JS-JOINTJS-1579578nvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-f3pp-32qc-36w4ghsaADVISORY
- github.com/clientIO/joint/pull/1514nvdThird Party AdvisoryWEB
- github.com/clientIO/joint/releases/tag/v3.4.2nvdRelease NotesThird Party AdvisoryWEB
News mentions
0No linked articles in our index yet.