PT-2021-24459 · Json Ptr · Json-Ptr

Published

2021-05-26

·

Updated

2021-05-26

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions: json-ptr versions prior to 2.1.0
Description: The issue allows an unscrupulous actor to execute arbitrary code. This occurs when un-sanitized user input is sent to json-ptr's get() method, making the project vulnerable to an injection-style issue.
Recommendations: For json-ptr versions prior to 2.1.0, update to version 2.1.0 or later to resolve the issue. As a temporary workaround, consider sanitizing all user input before sending it to the get() method to minimize the risk of exploitation.

Special Elements Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

GHSA-RRQV-VJRW-HRCR

Affected Products

Json-Ptr