MEDIUM5.6
GHSA-v5vg-g7rq-363w
Prototype Pollution in json-pointer
Quick fix
GHSA-v5vg-g7rq-363w — json-pointer: upgrade to the fixed version with the command below.
npm install json-pointer@0.6.2Details
This affects versions of package `json-pointer` up to and including `0.6.1`. A type confusion vulnerability can lead to a bypass of CVE-2020-7709 when the pointer components are arrays.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2021-23820[ADVISORY]
- https://github.com/manuelstofer/json-pointer/pull/36[WEB]
- https://github.com/manuelstofer/json-pointer/commit/931b0f9c7178ca09778087b4b0ac7e4f505620c2[WEB]
- https://github.com/manuelstofer/json-pointer[PACKAGE]
- https://github.com/manuelstofer/json-pointer/blob/master/index.js%23L78[WEB]
- https://snyk.io/vuln/SNYK-JS-JSONPOINTER-1577287[WEB]