You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
JSONata is a JSON query and transformation language. Starting in version 1.4.0 and prior to version 1.8.7 and 2.0.4, a malicious expression can use the transform operator to override properties on the Object constructor and prototype. This may lead to denial of service, remote code execution or other unexpected behavior in applications that evaluate user-provided JSONata expressions. This issue has been fixed in JSONata versions 1.8.7 and 2.0.4. Applications that evaluate user-provided expressions should update ASAP to prevent exploitation. As a workaround, one may apply the patch manually.
CVE-2024-27307 - Critical Severity Vulnerability
Vulnerable Library - jsonata-1.6.5.tgz
JSON query and transformation language
Library home page: https://registry.npmjs.org/jsonata/-/jsonata-1.6.5.tgz
Path to dependency file: /package.json
Path to vulnerable library: /node_modules/jsonata/package.json
Dependency Hierarchy:
Found in HEAD commit: f066b768ad80a1b199a84600ca9835323e9baee1
Found in base branch: master
Vulnerability Details
JSONata is a JSON query and transformation language. Starting in version 1.4.0 and prior to version 1.8.7 and 2.0.4, a malicious expression can use the transform operator to override properties on the
Object
constructor and prototype. This may lead to denial of service, remote code execution or other unexpected behavior in applications that evaluate user-provided JSONata expressions. This issue has been fixed in JSONata versions 1.8.7 and 2.0.4. Applications that evaluate user-provided expressions should update ASAP to prevent exploitation. As a workaround, one may apply the patch manually.Publish Date: 2024-03-06
URL: CVE-2024-27307
CVSS 3 Score Details (9.8)
Base Score Metrics:
Suggested Fix
Type: Upgrade version
Origin: GHSA-fqg8-vfv7-8fj8
Release Date: 2024-03-06
Fix Resolution (jsonata): 2.0.4
Direct dependency fix Resolution (node-red): 3.1.7
Step up your Open Source Security Game with Mend here
The text was updated successfully, but these errors were encountered: