High severity7.5NVD Advisory· Published Jan 21, 2022· Updated Jun 17, 2026
CVE-2021-23460
CVE-2021-23460
Description
The package min-dash before 3.8.1 are vulnerable to Prototype Pollution via the set method due to missing enforcement of key types.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
min-dashnpm | < 3.8.1 | 3.8.1 |
org.webjars.npm:min-dashMaven | < 3.8.1 | 3.8.1 |
Affected products
3- min-dash/min-dashdescription
- ghsa-coords2 versions
< 3.8.1+ 1 more
- (no CPE)range: < 3.8.1
- (no CPE)range: < 3.8.1
Patches
Vulnerability mechanics
References
10- github.com/bpmn-io/min-dash/pull/21nvdPatchThird Party AdvisoryWEB
- github.com/bpmn-io/min-dash/pull/21/commits/5ab05cbc4fd8d5eafb7db540c491ed0906b9d320nvdPatchThird Party Advisory
- snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-2342127nvdExploitMitigationPatchThird Party AdvisoryWEB
- snyk.io/vuln/SNYK-JS-MINDASH-2340605nvdExploitMitigationPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-2m53-83f3-562jghsaADVISORY
- github.com/bpmn-io/min-dash/blob/c4d579c0eb2ed0739592111c3906b198921d3f52/lib/object.js%23L32nvdBroken LinkThird Party Advisory
- nvd.nist.gov/vuln/detail/CVE-2021-23460ghsaADVISORY
- github.com/bpmn-io/min-dash/blob/c4d579c0eb2ed0739592111c3906b198921d3f52/lib/object.jsghsaWEB
- github.com/bpmn-io/min-dash/commit/2c6689e2aa29f4b66a4874a2f3003431e9db48d1ghsaWEB
- github.com/bpmn-io/min-dash/security/advisories/GHSA-2m53-83f3-562jghsaWEB
News mentions
0No linked articles in our index yet.