Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We鈥檒l occasionally send you account related emails.

Already on GitHub? Sign in to your account

[GHSA-9c47-m6qq-7p4h] Prototype Pollution in JSON5 via Parse Method #1540

Conversation

karlhorky
Copy link

@karlhorky karlhorky commented Dec 30, 2022

Updates

  • Affected products

Comments
json5/json5#298 (comment)


Ah, I think I fat-fingered this and submitted before it was finished. It seems I cannot edit this PR anymore either 馃槵

Anyway, what I was trying to do was report that it was also fixed in the v1 line (json5@1.0.2), as noted here:

So what I would suggest is that the vulnerability have two versions entries:

Affected versions Patched versions
< 1.0.2 1.0.2
>= 2.0.0, < 2.2.2 2.2.2

Similar to this xmldom vulnerability:

Screenshot 2022-12-30 at 19 19 20

@github
Copy link
Collaborator

github commented Dec 30, 2022

Hi there @jdgregson and @jordanbtucker! A community member has suggested an improvement to your security advisory. If approved, this change will affect the global advisory listed at github.com/advisories. It will not affect the version listed in your project repository.

This change will be reviewed by our highly-trained Security Curation Team. If you have thoughts or feedback, please share them in a comment here! If this PR has already been closed, you can start a new community contribution for this advisory

@github-actions github-actions bot changed the base branch from main to karlhorky/advisory-improvement-1540 December 30, 2022 18:10
@jordanbtucker
Copy link

@karlhorky Thanks for the suggestion. If you're not able to update this PR, it might be better to close this and open a new one. I'm traveling, so I'm not able to do that right now, but if you'd like to, I can review it and give my approval. I'm not exactly sure how the GHSA process works yet.

@jordanbtucker
Copy link

jordanbtucker commented Dec 30, 2022

I was able to open #1541 instead. This PR can be closed without merging. Thanks again!

/cc @karlhorky

@karlhorky
Copy link
Author

Ok great thanks @jordanbtucker !

@karlhorky karlhorky closed this Dec 30, 2022
@github-actions github-actions bot deleted the karlhorky-GHSA-9c47-m6qq-7p4h branch December 30, 2022 22:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

3 participants