This affects the package json before 10.0.0. It is possible to inject arbritary commands using the parseLookup function.
2020-08-30T08:15:11.900
2024-11-21T05:37:39.673
Modified
CVSSv3.1: 7.2 (HIGH)
AV:N/AC:L/Au:S/C:P/I:P/A:P
8.0
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | joyent | json | < 10.0.0 | Yes |
Application | oracle | commerce_guided_search | 11.3.2 | Yes |
Application | oracle | financial_services_crime_and_compliance_management_studio | 8.0.8.2.0 | Yes |
Application | oracle | financial_services_crime_and_compliance_management_studio | 8.0.8.3.0 | Yes |
Application | oracle | financial_services_regulatory_reporting_with_agilereporter | 8.0.9.6.3 | Yes |
Application | oracle | timesten_in-memory_database | < 21.1.1.1.0 | Yes |