Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-21534

Опубликовано: 11 окт. 2024
Источник: nvd
CVSS3: 9.8
EPSS Критический

Описание

All versions of the package jsonpath-plus are vulnerable to Remote Code Execution (RCE) due to improper input sanitization. An attacker can execute aribitrary code on the system by exploiting the unsafe default usage of vm in Node.

Note:

There were several attempts to fix it in versions 10.0.0-10.1.0 but it could still be exploited using different payloads.

EPSS

Процентиль: 100%
0.92275
Критический

9.8 Critical

CVSS3

Дефекты

CWE-94
CWE-94

Связанные уязвимости

CVSS3: 9.8
redhat
больше 1 года назад

All versions of the package jsonpath-plus are vulnerable to Remote Code Execution (RCE) due to improper input sanitization. An attacker can execute aribitrary code on the system by exploiting the unsafe default usage of vm in Node. **Note:** There were several attempts to fix it in versions [10.0.0-10.1.0](https://github.com/JSONPath-Plus/JSONPath/compare/v9.0.0...v10.1.0) but it could still be exploited using [different payloads](https://github.com/JSONPath-Plus/JSONPath/issues/226).

CVSS3: 9.8
github
больше 1 года назад

JSONPath Plus Remote Code Execution (RCE) Vulnerability

EPSS

Процентиль: 100%
0.92275
Критический

9.8 Critical

CVSS3

Дефекты

CWE-94
CWE-94