Описание
The value function in jsonpath 1.1.1 lib/index.js is vulnerable to Prototype Pollution.
A flaw was found in jsonpath. The value function is vulnerable to Prototype Pollution, a type of vulnerability that allows an attacker to inject or modify properties of an object's prototype. This can lead to various impacts, including arbitrary code execution, privilege escalation, or denial of service (DoS).
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Migration Toolkit for Virtualization | migration-toolkit-virtualization/mtv-console-plugin-rhel9 | Affected | ||
| Migration Toolkit for Virtualization | mtv-candidate/mtv-console-plugin-rhel9 | Will not fix | ||
| OpenShift Pipelines | openshift-pipelines/pipelines-hub-api-rhel8 | Will not fix | ||
| OpenShift Pipelines | openshift-pipelines/pipelines-hub-db-migration-rhel8 | Will not fix | ||
| OpenShift Pipelines | openshift-pipelines/pipelines-hub-ui-rhel8 | Affected | ||
| Red Hat Ansible Automation Platform 2 | ansible-on-clouds/aoc-azure-aap-installer-rhel9 | Affected | ||
| Red Hat Enterprise Linux AI (RHEL AI) 3 | rhelai3/bootc-cuda-rhel9 | Affected | ||
| Red Hat Enterprise Linux AI (RHEL AI) 3 | rhelai3/disk-image-cuda-rhel9 | Affected | ||
| Red Hat Fuse 7 | io.hawt-hawtio-online | Will not fix | ||
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-kf-notebook-controller-rhel8 | Not affected |
Показывать по
10
Дополнительная информация
Статус:
Important
Дефект:
CWE-502
https://bugzilla.redhat.com/show_bug.cgi?id=2433946jsonpath: jsonpath: Prototype Pollution vulnerability in the value function
EPSS
Процентиль: 21%
0.00066
Низкий
8.8 High
CVSS3
Связанные уязвимости
CVSS3: 9.8
nvd
2 месяца назад
The value function in jsonpath 1.1.1 lib/index.js is vulnerable to Prototype Pollution.
github
2 месяца назад
JSONPath vulnerable to Prototype Pollution due to insufficient input validation of object keys in lib/index.js
suse-cvrf
около 2 месяцев назад
Security update for golang-github-prometheus-prometheus
EPSS
Процентиль: 21%
0.00066
Низкий
8.8 High
CVSS3