CVE-2021-23408
21.07.2021, 16:15
This affects the package com.graphhopper:graphhopper-web-bundle before 3.2, from 4.0-pre1 and before 4.0. The URL parser could be tricked into adding or modifying properties of Object.prototype using a constructor or __proto__ payload.
Vendor | Product | Version |
---|---|---|
graphhopper | graphhopper | 𝑥 < 3.2 |
graphhopper | graphhopper | 4.0:pre1 |
graphhopper | graphhopper | 4.0:pre2 |
𝑥
= Vulnerable software versions
References