This affects the package jsonpointer
before 5.0.0
. A type confusion vulnerability can lead to a bypass of a previous Prototype Pollution fix when the pointer components are arrays.
{ "severity": "MODERATE", "github_reviewed": true, "cwe_ids": [ "CWE-1321", "CWE-843" ], "github_reviewed_at": "2021-11-04T16:58:08Z", "nvd_published_at": "2021-11-03T18:15:00Z" }