VDB
Sign up
MEDIUM5.6

GHSA-8gwj-8hxc-285w

Prototype Pollution in json-ptr

Quick fix

GHSA-8gwj-8hxc-285w — json-ptr: upgrade to the fixed version with the command below.

npm install json-ptr@3.0.0

Details

This affects the package `json-ptr` before `3.0.0`. A type confusion vulnerability can lead to a bypass of CVE-2020-7766 when the user-provided keys used in the pointer parameter are arrays.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/json-ptr
Introduced in: 0Fixed in: 3.0.0
Fixnpm install json-ptr@3.0.0

References