Arbitrary Code Execution Affecting json-ptr package, versions <2.1.0
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-JS-JSONPTR-1297099
- published 27 May 2021
- disclosed 26 May 2021
- credit Unknown
How to fix?
Upgrade json-ptr
to version 2.1.0 or higher.
Overview
json-ptr is a complete implementation of JSON Pointer (RFC 6901) for nodejs and modern browsers.
Affected versions of this package are vulnerable to Arbitrary Code Execution via the .get()
method.
References
CVSS Scores
version 3.1