VDB
Sign up
CRITICAL9.8

GHSA-5c5f-7vfq-3732

JMESPath for Ruby uses unsafe JSON.load when safe JSON.parse is preferable

Quick fix

GHSA-5c5f-7vfq-3732 — jmespath: upgrade to the fixed version with the command below.

bundle update jmespath

Details

jmespath.rb (aka JMESPath for Ruby) before 1.6.1 uses JSON.load in a situation where JSON.parse is preferable.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/jmespath
Introduced in: 0Fixed in: 1.6.1
Fixbundle update jmespath

References