Логотип exploitDog
bind:CVE-2025-1302
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-1302

Количество 3

Количество 3

redhat логотип

CVE-2025-1302

11 месяцев назад

Versions of the package jsonpath-plus before 10.3.0 are vulnerable to Remote Code Execution (RCE) due to improper input sanitization. An attacker can execute aribitrary code on the system by exploiting the unsafe default usage of eval='safe' mode. **Note:** This is caused by an incomplete fix for [CVE-2024-21534](https://security.snyk.io/vuln/SNYK-JS-JSONPATHPLUS-7945884).

CVSS3: 9.8
EPSS: Высокий
nvd логотип

CVE-2025-1302

11 месяцев назад

Versions of the package jsonpath-plus before 10.3.0 are vulnerable to Remote Code Execution (RCE) due to improper input sanitization. An attacker can execute aribitrary code on the system by exploiting the unsafe default usage of eval='safe' mode. **Note:** This is caused by an incomplete fix for [CVE-2024-21534](https://security.snyk.io/vuln/SNYK-JS-JSONPATHPLUS-7945884).

CVSS3: 9.8
EPSS: Высокий
github логотип

GHSA-hw8r-x6gr-5gjp

11 месяцев назад

JSONPath Plus allows Remote Code Execution

CVSS3: 9.8
EPSS: Высокий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2025-1302

Versions of the package jsonpath-plus before 10.3.0 are vulnerable to Remote Code Execution (RCE) due to improper input sanitization. An attacker can execute aribitrary code on the system by exploiting the unsafe default usage of eval='safe' mode. **Note:** This is caused by an incomplete fix for [CVE-2024-21534](https://security.snyk.io/vuln/SNYK-JS-JSONPATHPLUS-7945884).

CVSS3: 9.8
86%
Высокий
11 месяцев назад
nvd логотип
CVE-2025-1302

Versions of the package jsonpath-plus before 10.3.0 are vulnerable to Remote Code Execution (RCE) due to improper input sanitization. An attacker can execute aribitrary code on the system by exploiting the unsafe default usage of eval='safe' mode. **Note:** This is caused by an incomplete fix for [CVE-2024-21534](https://security.snyk.io/vuln/SNYK-JS-JSONPATHPLUS-7945884).

CVSS3: 9.8
86%
Высокий
11 месяцев назад
github логотип
GHSA-hw8r-x6gr-5gjp

JSONPath Plus allows Remote Code Execution

CVSS3: 9.8
86%
Высокий
11 месяцев назад

Уязвимостей на страницу