[NPM:GHSA-V88G-CGMW-V5XW] Prototype Pollution in Ajv

Severity Moderate
Affected Packages 1
Fixed Packages 1
CVEs 1

An issue was discovered in ajv.validate() in Ajv (aka Another JSON Schema Validator) 6.12.2. A carefully crafted JSON schema could be provided that allows execution of other code by prototype pollution. (While untrusted schemas are recommended against, the worst case of an untrusted schema should be a denial of service, not execution of code.)

Package Affected Version
pkg:npm/ajv < 6.12.3
Package Fixed Version
pkg:npm/ajv = 6.12.3
ID
NPM:GHSA-V88G-CGMW-V5XW
Severity
moderate
URL
https://github.com/advisories/GHSA-v88g-cgmw-v5xw
Published
2022-02-10T23:30:59
(2 years ago)
Modified
2023-01-27T05:08:06
(20 months ago)
Rights
NPM Security Team
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:npm/ajv ajv < 6.12.3
Fixed pkg:npm/ajv ajv = 6.12.3
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...