MEDIUM5.6
GHSA-8gwj-8hxc-285w
Prototype Pollution in json-ptr
Quick fix
GHSA-8gwj-8hxc-285w — json-ptr: upgrade to the fixed version with the command below.
npm install json-ptr@3.0.0Details
This affects the package `json-ptr` before `3.0.0`. A type confusion vulnerability can lead to a bypass of CVE-2020-7766 when the user-provided keys used in the pointer parameter are arrays.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2021-23509[ADVISORY]
- https://github.com/flitbit/json-ptr/pull/42[WEB]
- https://github.com/flitbit/json-ptr/commit/5dc458fbad1c382a2e3ca6d62e66ede3d92849ca[WEB]
- https://github.com/flitbit/json-ptr[PACKAGE]
- https://github.com/flitbit/json-ptr%23security-vulnerabilities-resolved[WEB]
- https://snyk.io/vuln/SNYK-JS-JSONPTR-1577291[WEB]