Описание
The value function in jsonpath 1.1.1 lib/index.js is vulnerable to Prototype Pollution.
Ссылки
- Third Party Advisory
- Product
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:dchester:jsonpath:1.1.1:*:*:*:*:node.js:*:*
EPSS
Процентиль: 35%
0.00419
Низкий
9.8 Critical
CVSS3
8.8 High
CVSS3
Дефекты
CWE-1321
CWE-502
Связанные уязвимости
CVSS3: 8.8
redhat
7 месяцев назад
The value function in jsonpath 1.1.1 lib/index.js is vulnerable to Prototype Pollution.
github
7 месяцев назад
JSONPath vulnerable to Prototype Pollution due to insufficient input validation of object keys in lib/index.js
suse-cvrf
6 месяцев назад
Security update for golang-github-prometheus-prometheus
suse-cvrf
5 месяцев назад
Security update 5.0.7 for Multi-Linux Manager Client Tools
EPSS
Процентиль: 35%
0.00419
Низкий
9.8 Critical
CVSS3
8.8 High
CVSS3
Дефекты
CWE-1321
CWE-502