JointjsCVEs & Vulnerabilities
2 CVEs affecting Jointjs products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.
2 CVEs→ All vendors
Most Affected Products
jointjs 2
CVE-2020-28480CRITICAL
The package jointjs before 3.3.0 are vulnerable to Prototype Pollution via util.setByPath (https://resources.jointjs.com/docs/jointjs/v3.2/joint.htmlutil.setByPath). The path used the access the object's key and set the value is not properly sanitized, leading to a Prototype Pollution.
19 Jan 2021
9.8
CVSS
CVE-2020-28479HIGH
The package jointjs before 3.3.0 are vulnerable to Denial of Service (DoS) via the unsetByPath function.
19 Jan 2021
7.5
CVSS
← PrevPage 1 / 1Next →