QID 982608
QID 982608: Nodejs (npm) Security Update for json8 (GHSA-7h43-gx24-p529)
This affects the package json8 before 1.0.3. The function adds in the target object the property specified in the path, however it does not properly check the key being set, leading to a prototype pollution.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-7h43-gx24-p529 for updates pertaining to this vulnerability.
Vendor References
- GHSA-7h43-gx24-p529 -
github.com/advisories/GHSA-7h43-gx24-p529
CVEs related to QID 982608
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-7h43-gx24-p529 | json8 |
|