QID 981612
QID 981612: Nodejs (npm) Security Update for jpv (GHSA-rh46-3fgc-mvrf)
In jpv (aka Json Pattern Validator) before 2.1.1, compareCommon() can be bypassed because certain internal attributes can be overwritten via a conflicting name, as demonstrated by 'constructor': {'name':'Array'}. This affects validate(). Hence, a crafted payload can overwrite this builtin attribute to manipulate the type detection result.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-rh46-3fgc-mvrf for updates pertaining to this vulnerability.
Vendor References
- GHSA-rh46-3fgc-mvrf -
github.com/advisories/GHSA-rh46-3fgc-mvrf
CVEs related to QID 981612
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-rh46-3fgc-mvrf | jpv |
|