Lucene search

K
osvGoogleOSV:CVE-2021-23624
HistoryNov 03, 2021 - 6:15 p.m.

CVE-2021-23624

2021-11-0318:15:08
Google
osv.dev
5

6.6 Medium

AI Score

Confidence

Low

0.012 Low

EPSS

Percentile

84.9%

This affects the package dotty before 0.1.2. A type confusion vulnerability can lead to a bypass of CVE-2021-25912 when the user-provided keys used in the path parameter are arrays.

CPENameOperatorVersion
dottyeq0.1.1
dottyeq0.0.2
dottyeq0.1.0
dottyeq0.0.1

6.6 Medium

AI Score

Confidence

Low

0.012 Low

EPSS

Percentile

84.9%