Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-x5r6-x823-9848

Опубликовано: 10 мая 2021
Источник: github
Github: Прошло ревью
CVSS3: 7.3

Описание

Arbitrary Code Execution in json-ptr

npm json-ptr before 2.1.0 has an arbitrary code execution vulnerability. The issue occurs in the set operation when the force flag is set to true. The function recursively set the property in the target object, however it does not properly check the key being set, leading to a prototype pollution.

Пакеты

Наименование

json-ptr

npm
Затронутые версииВерсия исправления

< 2.1.0

2.1.0

EPSS

Процентиль: 77%
0.01064
Низкий

7.3 High

CVSS3

Дефекты

CWE-1321
CWE-400
CWE-74

Связанные уязвимости

CVSS3: 7.3
nvd
около 5 лет назад

This affects all versions of package json-ptr. The issue occurs in the set operation (https://flitbit.github.io/json-ptr/classes/_src_pointer_.jsonpointer.htmlset) when the force flag is set to true. The function recursively set the property in the target object, however it does not properly check the key being set, leading to a prototype pollution.

EPSS

Процентиль: 77%
0.01064
Низкий

7.3 High

CVSS3

Дефекты

CWE-1321
CWE-400
CWE-74