Description
jpv (aka Json Pattern Validator) before 2.2.2 does not properly validate input, as demonstrated by a corrupted array.
Recommendation
Update the jpv package to the latest compatible version. Followings are version details:
- Affected version(s): < 2.2.2
- Patched version(s): 2.2.2
References
- GHSA-vh6r-g38f-q3w8
- blog.sonatype.com
- www.npmjs.com
- CVE-2020-17479
- CWE-20
- CAPEC-310
- OWASP 2021-A3
- OWASP 2021-A6
Related Issues
- Validation bypass is possible in Json Pattern Validator - CVE-2019-19507
- ECDSA signature validation vulnerability by accepting wrong ASN.1 encoding in jsrsasign - CVE-2020-14966
- File restriction bypass in socket.io-file - CVE-2020-24807
- Improper Input Validation in SocksJS-Node - CVE-2020-7693
You might also like:
- Tags:
- npm
- jpv
Anything's wrong? Let us know Last updated on February 01, 2023


