Description
A vulnerability, which was classified as critical, has been found in json-pointer up to 0.6.1. Affected by this issue is the function set of the file index.js. The manipulation leads to improperly controlled modification of object prototype attributes (‘prototype pollution’). The attack may be launched remotely. Upgrading to version 0.6.
Recommendation
Update the json-pointer package to the latest compatible version. Followings are version details:
- Affected version(s): < 0.6.2
- Patched version(s): 0.6.2
References
Related Issues
- deep-parse-json vulnerable to Prototype Pollution - CVE-2022-42743
- Prototype pollution in json-pointer - json-pointer - CVE-2020-7709
- Prototype Pollution in json-pointer - CVE-2021-23820
- steal vulnerable to Prototype Pollution via alias variable - CVE-2022-37265
You might also like:
- Tags:
- npm
- json-pointer
Anything's wrong? Let us know Last updated on April 04, 2024


