CVE-2020-7709: Prototype pollution in json-pointer
(updated )
This affects the package json-pointer before 0.6.1. Multiple reference of object using slash is supported.
References
- github.com/advisories/GHSA-7mg4-w3w5-x5pc
- github.com/manuelstofer/json-pointer
- github.com/manuelstofer/json-pointer/pull/34
- github.com/manuelstofer/json-pointer/pull/34/files
- nvd.nist.gov/vuln/detail/CVE-2020-7709
- snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-598862
- snyk.io/vuln/SNYK-JS-JSONPOINTER-596925
- www.npmjs.com/package/json-pointer
Detect and mitigate CVE-2020-7709 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →