{"id":"GHSA-cq8r-fc3q-6hg2","summary":"Denial of Service (DoS) via the unsetByPath function in jsjoints","details":"The package jointjs before 3.3.0 are vulnerable to Denial of Service (DoS) via the unsetByPath function.","aliases":["CVE-2020-28479"],"modified":"2024-11-14T01:42:21.552570Z","published":"2021-04-13T15:29:40Z","database_specific":{"nvd_published_at":"2021-01-19T15:15:00Z","cwe_ids":["CWE-400"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2021-04-06T20:51:59Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-28479"},{"type":"WEB","url":"https://github.com/clientIO/joint/commit/ec7ab01b512a3c06a9944a25d50f255bf07c3499"},{"type":"WEB","url":"https://github.com/clientIO/joint/releases/tag/v3.3.0"},{"type":"WEB","url":"https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-1062040"},{"type":"WEB","url":"https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1062039"},{"type":"WEB","url":"https://snyk.io/vuln/SNYK-JS-JOINTJS-1062038"}],"affected":[{"package":{"name":"jointjs","ecosystem":"npm","purl":"pkg:npm/jointjs"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"3.3.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/04/GHSA-cq8r-fc3q-6hg2/GHSA-cq8r-fc3q-6hg2.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}