PT-2022-11692 · Unknown · Starcounter-Jack Json-Patch

Alromh87

·

Published

2022-12-25

·

Updated

2024-05-17

·

CVE-2021-4279

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Starcounter-Jack JSON-Patch versions up to 3.1.0
Description A vulnerability has been found in Starcounter-Jack JSON-Patch, classified as problematic. This issue affects unknown code and leads to improperly controlled modification of object prototype attributes, known as 'prototype pollution'. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 3.1.1 can address this issue.
Recommendations For Starcounter-Jack JSON-Patch versions up to 3.1.0, upgrade to version 3.1.1 to address the issue. As a temporary workaround, consider restricting access to the affected component until the upgrade is applied.

Exploit

Fix

Prototype Pollution

Weakness Enumeration

Related Identifiers

CVE-2021-4279
GHSA-8GH8-HQWG-XF34

Affected Products

Starcounter-Jack Json-Patch