{"id":"CVE-2021-23820","aliases":[],"url":"https://o3.security/vulnerability/CVE-2021-23820","summary":"This affects all versions of package json-pointer. A type confusion vulnerability can lead to a bypass of CVE-2020-7709 when the pointer components are arrays.","details":"This affects all versions of package json-pointer. A type confusion vulnerability can lead to a bypass of CVE-2020-7709 when the pointer components are arrays.","published":"2021-11-03T18:15:08.287","modified":"2026-06-17T03:38:53.627","cvss":{"score":5.6,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L"},"epss":null,"cisaKev":null,"exploitsKnown":2,"affectedPackages":[],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/manuelstofer/json-pointer/blob/master/index.js%23L78"},{"type":"EXPLOIT","url":"https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1910686"},{"type":"EXPLOIT","url":"https://snyk.io/vuln/SNYK-JS-JSONPOINTER-1577287"},{"type":"ADVISORY","url":"https://github.com/manuelstofer/json-pointer/blob/master/index.js%23L78"},{"type":"EXPLOIT","url":"https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1910686"},{"type":"EXPLOIT","url":"https://snyk.io/vuln/SNYK-JS-JSONPOINTER-1577287"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-06-17T03:38:53.627"}}