2.2.2
9 years ago
1 months ago
Known vulnerabilities in the jsonata package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
jsonata is a JSON query and transformation language Affected versions of this package are vulnerable to Arbitrary Code Injection via the How to fix Arbitrary Code Injection? Upgrade | <1.8.8>=2.0.0 <2.2.0 |
jsonata is a JSON query and transformation language Affected versions of this package are vulnerable to Prototype Pollution via unsafe object creation patterns throughout the codebase ( How to fix Prototype Pollution? Upgrade | <1.8.8>=2.0.0 <2.2.1 |
jsonata is a JSON query and transformation language Affected versions of this package are vulnerable to Arbitrary Code Injection via crafted expressions that exploit the How to fix Arbitrary Code Injection? Upgrade | <1.8.8>=2.0.0 <2.2.1 |
jsonata is a JSON query and transformation language Affected versions of this package are vulnerable to Regular Expression Denial of Service (ReDoS) via the How to fix Regular Expression Denial of Service (ReDoS)? Upgrade | <2.2.0 |
jsonata is a JSON query and transformation language Affected versions of this package are vulnerable to Prototype Pollution via several functions, including How to fix Prototype Pollution? Upgrade | <2.2.1 |