Description
jpv (aka Json Pattern Validator) before 2.2.2 does not properly validate input, as demonstrated by a corrupted array.
Recommendation
Update the jpv package to the latest compatible version. Followings are version details:
- Affected version(s): < 2.2.2
- Patched version(s): 2.2.2
References
Could your website be exposed too?
SmartScanner can check your website for Validation bypass in jpv and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Validation bypass is possible in Json Pattern Validator - CVE-2019-19507
- ECDSA signature validation vulnerability by accepting wrong ASN.1 encoding in jsrsasign - CVE-2020-14966
- File restriction bypass in socket.io-file - CVE-2020-24807
- Improper Input Validation in SocksJS-Node - CVE-2020-7693
You might also like:
See something that needs correcting? Let us knowUpdated February 01, 2023


