{"id":"CVE-2021-23624","details":"This affects the package dotty before 0.1.2. A type confusion vulnerability can lead to a bypass of CVE-2021-25912 when the user-provided keys used in the path parameter are arrays.","aliases":["GHSA-6g47-63mv-qpgh","SNYK-JS-DOTTY-1577292"],"modified":"2026-07-08T06:50:01.172373138Z","published":"2021-11-03T18:15:08.130Z","database_specific":{"unresolved_ranges":[{"source":"CPE_RANGE","vendor_product":"dotty_project:dotty","cpes":["cpe:2.3:a:dotty_project:dotty:*:*:*:*:*:*:*:*"],"extracted_events":[{"fixed":"0.1.2"}]},{"extracted_events":[{"fixed":"0.1.2"}],"source":"DESCRIPTION"}]},"references":[{"type":"FIX","url":"https://github.com/deoxxa/dotty/commit/88f61860dcc274a07a263c32cbe9d44c24ef02d7"},{"type":"FIX","url":"https://snyk.io/vuln/SNYK-JS-DOTTY-1577292"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/deoxxa/dotty","events":[{"introduced":"0"},{"fixed":"88f61860dcc274a07a263c32cbe9d44c24ef02d7"}],"database_specific":{"source":"REFERENCES"}}],"versions":["v0.1.1","v0.1.0","0.0.2"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-23624.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}