CVE-2021-23413
25.07.2021, 13:15
This affects the package jszip before 3.7.0. Crafting a new zip file with filenames set to Object prototype values (e.g __proto__, toString, etc) results in a returned object with a modified prototype instance.Enginsight
| Vendor | Product | Version |
|---|---|---|
| jszip_project | jszip | 𝑥 < 3.7.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
References