Description
A vulnerability, which was classified as critical, has been found in json-pointer up to 0.6.1. Affected by this issue is the function set of the file index.js. The manipulation leads to improperly controlled modification of object prototype attributes (‘prototype pollution’). The attack may be launched remotely. Upgrading to version 0.6.
Recommendation
Update the json-pointer package to the latest compatible version. Followings are version details:
- Affected version(s): < 0.6.2
- Patched version(s): 0.6.2
References
Could your website be exposed too?
SmartScanner can check your website for json-pointer vulnerable to Prototype Pollution and gives you actionable findings to investigate.
Start a free scanRelated Issues
- deep-parse-json vulnerable to Prototype Pollution - CVE-2022-42743
- Prototype pollution in json-pointer - json-pointer - CVE-2020-7709
- Prototype Pollution in json-pointer - CVE-2021-23820
- steal vulnerable to Prototype Pollution via alias variable - CVE-2022-37265


