Medium severity5.6NVD Advisory· Published Nov 3, 2021· Updated Jun 17, 2026
CVE-2021-23624
CVE-2021-23624
Description
This affects the package dotty before 0.1.2. A type confusion vulnerability can lead to a bypass of CVE-2021-25912 when the user-provided keys used in the path parameter are arrays.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
dottynpm | < 0.1.2 | 0.1.2 |
Affected products
3- dotty/dottydescription
Patches
Vulnerability mechanics
References
4- github.com/deoxxa/dotty/commit/88f61860dcc274a07a263c32cbe9d44c24ef02d7nvdPatchThird Party AdvisoryWEB
- snyk.io/vuln/SNYK-JS-DOTTY-1577292nvdExploitMitigationPatchThird Party AdvisoryVDB EntryWEB
- github.com/advisories/GHSA-6g47-63mv-qpghghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2021-23624ghsaADVISORY
News mentions
0No linked articles in our index yet.