Server-side Request Forgery (SSRF) Affecting jsoneditor package, versions <2.2.2
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-JS-JSONEDITOR-1315828
- published 2 Jul 2021
- disclosed 2 Jul 2021
- credit Unknown
How to fix?
Upgrade jsoneditor
to version 2.2.2 or higher.
Overview
jsoneditor is a web-based tool to view, edit, format, and validate JSON.
Affected versions of this package are vulnerable to Server-side Request Forgery (SSRF) via the server side file retriever script of the web application. This could allow an attacker to read files on the server.
References
CVSS Scores
version 3.1