PT-2020-19734 · Json · Json

Po6Ix

·

Published

2020-08-30

·

Updated

2022-12-03

·

CVE-2020-7712

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions json versions prior to 10.0.0
Description The issue allows for the injection of arbitrary commands using the parseLookup function.
Recommendations For versions prior to 10.0.0, update to version 10.0.0 or later to resolve the issue. As a temporary workaround, consider restricting the use of the parseLookup function until a patch is available.

Exploit

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2020-7712
GHSA-3C6G-PVG8-GQW2
SNYK-JAVA-ORGWEBJARS-608932
SNYK-JAVA-ORGWEBJARSNPM-608931
SNYK-JS-JSON-597481

Affected Products

Json