CVE-2021-23413
25.07.2021, 13:15
This affects the package jszip before 3.7.0. Crafting a new zip file with filenames set to Object prototype values (e.g __proto__, toString, etc) results in a returned object with a modified prototype instance.Enginsight
Vendor | Product | Version |
---|---|---|
jszip_project | jszip | 𝑥 < 3.7.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
References