VDB
Sign up
MEDIUM5.6

GHSA-v5vg-g7rq-363w

Prototype Pollution in json-pointer

Quick fix

GHSA-v5vg-g7rq-363w — json-pointer: upgrade to the fixed version with the command below.

npm install json-pointer@0.6.2

Details

This affects versions of package `json-pointer` up to and including `0.6.1`. A type confusion vulnerability can lead to a bypass of CVE-2020-7709 when the pointer components are arrays.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/json-pointer
Introduced in: 0Fixed in: 0.6.2
Fixnpm install json-pointer@0.6.2

References