PT-2022-26533 · Unknown · Deep-Parse-Json

Carlos Bello

·

Published

2022-11-03

·

Updated

2025-04-24

·

CVE-2022-42743

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions deep-parse-json version 1.0.2
Description The issue allows an external attacker to edit or add new properties to an object. This is possible because the application does not correctly validate the incoming JSON keys, thus allowing the proto property to be edited.
Recommendations For deep-parse-json version 1.0.2, consider validating incoming JSON keys to prevent the proto property from being edited as a temporary workaround until a patch is available.

Exploit

Fix

Prototype Pollution

Weakness Enumeration

Related Identifiers

CVE-2022-42743
GHSA-FF9J-PWXG-Q5P2

Affected Products

Deep-Parse-Json