AIKIDO-2024-10345

jsonpath-plus is vulnerable to Remote code execution

90

Critical

jsonpath-plus js

AIKIDO-2024-10345: jsonpath-plus is vulnerable to Remote code execution in versions 0.1.0 - 10.0.0.

Remote code execution
Vuln in 0.1.0 - 10.0.0
Fixed in 10.0.1
No CVE available
TL;DR

Affected versions of the package are vulnerable to Remote code execution. CVE-2024-21534 was not solved entirely in version 10.0.0, for a certain input RCE is still possible.

Who does this affect?

You're affected if you are using a version which is within vulnerability ranges.

How can it be fixed?

Upgrade jsonpath-plus library to patch version.

Background info

Link to vendor website

Are you
to these issues?
Connect your GitHub, GitLab, Bitbucket or Azure DevOps account to start scanning your repos for free.
Start For Free
Your data won't be shared · Read-only access
Logo
© 2024 Aikido Security BV | BE0792914919
🇪🇺 Grauwpoort 1, 9000 Ghent, Belgium
🇺🇸 95 Third St, 2nd Fl, San Francisco, CA 94103, US