Description
This affects versions of package json-pointer up to and including 0.6.1. A type confusion vulnerability can lead to a bypass of CVE-2020-7709 when the pointer components are arrays.
Recommendation
Update the json-pointer package to the latest compatible version. Followings are version details:
- Affected version(s): <= 0.6.1
- Patched version(s): 0.6.2
References
Related Issues
- Prototype pollution in json-pointer - json-pointer - CVE-2020-7709
- json-pointer vulnerable to Prototype Pollution - CVE-2022-4742
- Starcounter-Jack JSON-Patch Prototype Pollution vulnerability - CVE-2021-4279
- json-schema is vulnerable to Prototype Pollution - CVE-2021-3918
You might also like:
- Tags:
- npm
- json-pointer
Anything's wrong? Let us know Last updated on January 27, 2023


