CVE-2020-7712

This affects the package json before 10.0.0. It is possible to inject arbritary commands using the parseLookup function.

Summary:

This affects the package json before 10.0.0. It is possible to inject arbritary commands using the parseLookup function.

Reference Links(if available):

  • https://snyk.io/vuln/SNYK-JS-JSON-597481
  • https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARS-608932
  • https://github.com/trentm/json/pull/145
  • https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-608931
  • https://github.com/trentm/json/issues/144
  • CVSS Score (if available)

    v2: / MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P

    v3: / HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

    Links to Exploits(if available)