PT-2021-7248 · Npm · Json-Pointer

Alessio Della Libera

·

Published

2021-11-03

·

Updated

2025-07-02

·

CVE-2021-23820

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions json-pointer versions up to and including 0.6.1
Description A type confusion issue in the json-pointer package can lead to a bypass when the pointer components are arrays. This can potentially allow a remote attacker to execute arbitrary code or cause a denial of service. The issue is related to errors in mixing data types.
Recommendations For versions up to and including 0.6.1, update to a version that fixes this issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Prototype Pollution

Type Confusion

Weakness Enumeration

Related Identifiers

BDU:2022-04137
CVE-2021-23820
GHSA-V5VG-G7RQ-363W
SNYK-JAVA-ORGWEBJARSNPM-1910686
SNYK-JS-JSONPOINTER-1577287

Affected Products

Json-Pointer