Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-21534

Опубликовано: 11 окт. 2024
Источник: nvd
CVSS3: 9.8
EPSS Низкий

Описание

All versions of the package jsonpath-plus are vulnerable to Remote Code Execution (RCE) due to improper input sanitization. An attacker can execute aribitrary code on the system by exploiting the unsafe default usage of vm in Node.

Note:

There were several attempts to fix it in versions 10.0.0-10.1.0 but it could still be exploited using different payloads.

EPSS

Процентиль: 95%
0.09017
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-94
CWE-94

Связанные уязвимости

CVSS3: 9.8
redhat
почти 2 года назад

All versions of the package jsonpath-plus are vulnerable to Remote Code Execution (RCE) due to improper input sanitization. An attacker can execute aribitrary code on the system by exploiting the unsafe default usage of vm in Node. **Note:** There were several attempts to fix it in versions [10.0.0-10.1.0](https://github.com/JSONPath-Plus/JSONPath/compare/v9.0.0...v10.1.0) but it could still be exploited using [different payloads](https://github.com/JSONPath-Plus/JSONPath/issues/226).

CVSS3: 9.8
github
почти 2 года назад

JSONPath Plus Remote Code Execution (RCE) Vulnerability

EPSS

Процентиль: 95%
0.09017
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-94
CWE-94