PT-2022-28063 · Unknown · Json-Pointer

·

CVE-2022-4742

·

Published

2022-12-26

·

Updated

2024-05-17

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions json-pointer versions up to 0.6.1
Description A critical issue has been found in the function set of the file index.js, leading to improperly controlled modification of object prototype attributes, also known as 'prototype pollution'. This issue can be exploited remotely.
Recommendations For json-pointer versions up to 0.6.1, upgrade to version 0.6.2 to address this issue. As a temporary workaround, consider restricting access to the function set of the file index.js until the upgrade is applied.

Exploit

Fix

Prototype Pollution

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-4742
GHSA-6XRF-Q977-5VGC

Affected Products

Json-Pointer