3.7.7
11 years ago
1 years ago
Package is deprecated
Known vulnerabilities in the jointjs package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version | 
|---|---|
| 
 jointjs is a JavaScript diagramming library. It can be used to create either static diagrams or, and more importantly, fully interactive diagramming tools and application builders. Affected versions of this package are vulnerable to Prototype Pollution. A type confusion vulnerability can lead to a bypass of CVE-2020-28480 when the user-provided keys used in the  PoCHow to fix Prototype Pollution? Upgrade  | <3.4.2 | 
| 
 jointjs is a JavaScript diagramming library. It can be used to create either static diagrams or, and more importantly, fully interactive diagramming tools and application builders. Affected versions of this package are vulnerable to Denial of Service (DoS) via the  How to fix Denial of Service (DoS)? Upgrade  | <3.3.0 | 
| 
 jointjs is a JavaScript diagramming library. It can be used to create either static diagrams or, and more importantly, fully interactive diagramming tools and application builders. Affected versions of this package are vulnerable to Prototype Pollution via  PoCHow to fix Prototype Pollution? Upgrade  | <3.3.0 |