MEDIUM6.0
GHSA-7mg4-w3w5-x5pc
Prototype pollution in json-pointer
Quick fix
GHSA-7mg4-w3w5-x5pc — json-pointer: upgrade to the fixed version with the command below.
npm install json-pointer@0.6.1Details
This affects the package json-pointer before 0.6.1. Multiple reference of object using slash is supported.
Are you affected?
Enter the version of the package you're using.
Affected packages
Maven/org.webjars.npm:json-pointer
Introduced in:
0Fixed in: 0.6.1Fix
# pom.xml: bump <version>0.6.1</version> for org.webjars.npm:json-pointerReferences
- https://nvd.nist.gov/vuln/detail/CVE-2020-7709[ADVISORY]
- https://github.com/manuelstofer/json-pointer/pull/34[WEB]
- https://github.com/manuelstofer/json-pointer/pull/34/files[WEB]
- https://github.com/manuelstofer/json-pointer[PACKAGE]
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-598862[WEB]
- https://snyk.io/vuln/SNYK-JS-JSONPOINTER-596925[WEB]
- https://www.npmjs.com/package/json-pointer[WEB]