CVE-2021-23438
Published Sep 1, 2021This affects the package mpath before 0.8.4. A type confusion vulnerability can lead to a bypass of CVE-2018-16490. In particular, the condition ignoreProperties.indexOf(parts[i])…
Vendor/product archive
2 CVEs tagged to mpath_project / mpath — 0 Critical, 1 High, 1 Medium, 0 Low, 0 Unrated.
This affects the package mpath before 0.8.4. A type confusion vulnerability can lead to a bypass of CVE-2018-16490. In particular, the condition ignoreProperties.indexOf(parts[i])…
A prototype pollution vulnerability was found in module mpath <0.5.1 that allows an attacker to inject arbitrary properties onto Object.prototype.