A type confusion vulnerability can lead to a bypass of CVE-2018-16490. In particular, the condition ignoreProperties.indexOf(parts[i]) !== -1 returns -1 if parts[i] is ['__proto__']. External Reference: https://snyk.io/vuln/SNYK-JS-MPATH-1577289
The vulnerable component is not longer shipped with RHACM. Marking RHACM as not affected.
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2021-23438