VYPR
Vendor

Dotty Project

Products
1
CVEs
2
Across products
2
Status
Private

Products

1

Recent CVEs

2
  • CVE-2021-25912CriFeb 2, 2021
    risk 0.57cvss 9.8epss 0.03

    Prototype pollution vulnerability in 'dotty' versions 0.0.1 through 0.1.0 allows attackers to cause a denial of service and may lead to remote code execution.

  • CVE-2021-23624MedNov 3, 2021
    risk 0.29cvss 5.6epss 0.01

    This affects the package dotty before 0.1.2. A type confusion vulnerability can lead to a bypass of CVE-2021-25912 when the user-provided keys used in the path parameter are arrays.