Description
A vulnerability has been found in Starcounter-Jack JSON-Patch up to 3.1.0 and classified as problematic. This vulnerability affects unknown code. The manipulation leads to improperly controlled modification of object prototype attributes (‘prototype pollution’). The attack can be initiated remotely.
Recommendation
Update the fast-json-patch package to the latest compatible version. Followings are version details:
- Affected version(s): < 3.1.1
- Patched version(s): 3.1.1
References
- GHSA-8gh8-hqwg-xf34
- blog.effectrenan.com
- vuldb.com
- www.huntr.dev
- CVE-2021-4279
- CWE-1321
- CAPEC-310
- OWASP 2021-A6
Related Issues
- Prototype Pollution Vulnerability in object-collider - CVE-2021-25914
- Prototype Pollution in json-pointer - CVE-2021-23820
- Prototype pollution vulnerability in 'patchmerge - CVE-2021-25916
- Prototype pollution vulnerability in js-extend - CVE-2021-25945
You might also like:
- Tags:
- npm
- fast-json-patch
Anything's wrong? Let us know Last updated on March 01, 2024


