MEDIUM5.9
GHSA-3hvj-2783-34x2
njwt Prototype Pollution vulnerability
Quick fix
GHSA-3hvj-2783-34x2 — njwt: upgrade to the fixed version with the command below.
npm install njwt@2.0.1Details
njwt up to v0.4.0 was discovered to contain a prototype pollution in the `Parser.prototype.parse` method.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2024-34273[ADVISORY]
- https://github.com/jwtk/njwt/issues/105[WEB]
- https://github.com/jwtk/njwt/commit/ec9483b6eec1150d56f772ddd308c2bbdf2f98f4[WEB]
- https://github.com/chrisandoryan/vuln-advisory/blob/main/nJwt/CVE-2024-34273.md[WEB]
- https://github.com/jwtk/njwt[PACKAGE]