GHSA-x5r6-x823-9848

    Dashboard / Vulnerabilities / GHSA-x5r6-x823-9848

    GHSA-x5r6-x823-9848

    Published: 10 May 2021Last Modified: 14 Jan 2025
    Aliases:

    Summary: Arbitrary Code Execution in json-ptr

    Details: npm `json-ptr` before 2.1.0 has an arbitrary code execution vulnerability. The issue occurs in the [set operation](https://flitbit.github.io/json-ptr/classes/_src_pointer_.jsonpointer.htmlset) when the force flag is set to true. The function recursively set the property in the target object, however it does not properly check the key being set, leading to a prototype pollution.

    Affected packages

    Package

    Name: json-ptr

    Purl: pkg:npm/json-ptr

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -2.1.0

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-x5r6-x823-9848 | CVE-DB