Vulnerabilities/

jsonic was discovered to contain a prototype pollution via the function empty.

Severity:
High

Description

rjrodger jsonic-next v2.12.1 was discovered to contain a prototype pollution via the function empty. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.

Recommendation

No fix is available yet. Followings are affected versions:

References

Related Issues

Tags:
npm
jsonic
Anything's wrong? Let us know Last updated on July 12, 2024

This issue is available in SmartScanner Professional

See Pricing