Description
This affects versions of package json-pointer up to and including 0.6.1. A type confusion vulnerability can lead to a bypass of CVE-2020-7709 when the pointer components are arrays.
Recommendation
Update the json-pointer package to the latest compatible version. Followings are version details:
- Affected version(s): <= 0.6.1
- Patched version(s): 0.6.2
References
Could your website be exposed too?
SmartScanner can check your website for Prototype Pollution in json-pointer and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Prototype pollution in json-pointer - json-pointer - CVE-2020-7709
- json-pointer vulnerable to Prototype Pollution - CVE-2022-4742
- Starcounter-Jack JSON-Patch Prototype Pollution vulnerability - CVE-2021-4279
- json-schema is vulnerable to Prototype Pollution - CVE-2021-3918
You might also like:
See something that needs correcting? Let us knowUpdated January 27, 2023


