Open
Description
There appear to be two advisories in the GitHub Advisory Database describing the same prototype pollution vulnerability in the min-dash
JavaScript package:
-
- No CVE ID
- Limited metadata
- No fix commit or external references
-
- Has a CVE: CVE-2021-23460
- Provides a clear description, references, and the fix commit:
- Patch commit: bpmn-io/min-dash@289e6c7
These two advisories describe the same underlying issue and request to withdraw GHSA-2m53-83f3-562j, as GHSA-fm93-fhh2-cg2c is more complete and includes the canonical CVE (CVE-2021-23460), along with additional references and context.
Metadata
Metadata
Assignees
Labels
No labels