Lucene search

K
osvGoogleOSV:GHSA-6G47-63MV-QPGH
HistoryNov 08, 2021 - 5:55 p.m.

Prototype Pollution in dotty

2021-11-0817:55:48
Google
osv.dev
20

0.012 Low

EPSS

Percentile

84.9%

This affects the package dotty before 0.1.2. A type confusion vulnerability can lead to a bypass of CVE-2021-25912 when the user-provided keys used in the path parameter are arrays.

CPENameOperatorVersion
dottylt0.1.2

0.012 Low

EPSS

Percentile

84.9%