CVE-2020-28480: Prototype Pollution
(updated )
The package jointjs is vulnerable to Prototype Pollution via util.setByPath
(https://resources.jointjs.com/docs/jointjs/v3.2/joint.htmlutil.setByPath). The path used the access the object’s key and set the value is not properly sanitized, leading to a Prototype Pollution.
References
Detect and mitigate CVE-2020-28480 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →