Количество 2
Количество 2
CVE-2020-7766
This affects all versions of package json-ptr. The issue occurs in the set operation (https://flitbit.github.io/json-ptr/classes/_src_pointer_.jsonpointer.htmlset) when the force flag is set to true. The function recursively set the property in the target object, however it does not properly check the key being set, leading to a prototype pollution.
GHSA-x5r6-x823-9848
Arbitrary Code Execution in json-ptr
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2020-7766 This affects all versions of package json-ptr. The issue occurs in the set operation (https://flitbit.github.io/json-ptr/classes/_src_pointer_.jsonpointer.htmlset) when the force flag is set to true. The function recursively set the property in the target object, however it does not properly check the key being set, leading to a prototype pollution. | CVSS3: 7.3 | 1% Низкий | около 5 лет назад | |
GHSA-x5r6-x823-9848 Arbitrary Code Execution in json-ptr | CVSS3: 7.3 | 1% Низкий | больше 4 лет назад |
Уязвимостей на страницу