NVD - CVE-2024-21534 (original) (raw)

Change History

5 change records found show changes

CVE Modified by Snyk 11/18/2024 6:15:06 AM

Action Type Old Value New Value
Changed Description Versions of the package jsonpath-plus before 10.0.7 are vulnerable to Remote Code Execution (RCE) due to improper input sanitization. An attacker can execute aribitrary code on the system by exploiting the unsafe default usage of vm in Node. **Note:** There was an attempt to fix it in version [10.0.0](https://github.com/JSONPath-Plus/JSONPath/commit/6b2f1b4c234292c75912b790bf7e2d7339d4ccd3) but it could still be exploited using [different payloads](https://github.com/JSONPath-Plus/JSONPath/issues/226). All versions of the package jsonpath-plus are vulnerable to Remote Code Execution (RCE) due to improper input sanitization. An attacker can execute aribitrary code on the system by exploiting the unsafe default usage of vm in Node. **Note:** There were several attempts to fix it in versions [10.0.0-10.1.0](https://github.com/JSONPath-Plus/JSONPath/compare/v9.0.0...v10.1.0) but it could still be exploited using [different payloads](https://github.com/JSONPath-Plus/JSONPath/issues/226).
Added Reference Snyk https://github.com/JSONPath-Plus/JSONPath/compare/v9.0.0...v10.1.0 [No types assigned]
Removed Reference Snyk https://github.com/JSONPath-Plus/JSONPath/commit/6b2f1b4c234292c75912b790bf7e2d7339d4ccd3
Removed Reference Snyk https://github.com/JSONPath-Plus/JSONPath/commit/b70aa713553caf838a63bac923195a5bc541fd72

CVE Modified by Snyk 10/20/2024 8:15:02 AM

Action Type Old Value New Value
Changed Description Versions of the package jsonpath-plus before 10.0.0 are vulnerable to Remote Code Execution (RCE) due to improper input sanitization. An attacker can execute aribitrary code on the system by exploiting the unsafe default usage of vm in Node. **Note:** The unsafe behavior is still available after applying the fix but it is not turned on by default. Versions of the package jsonpath-plus before 10.0.7 are vulnerable to Remote Code Execution (RCE) due to improper input sanitization. An attacker can execute aribitrary code on the system by exploiting the unsafe default usage of vm in Node. **Note:** There was an attempt to fix it in version [10.0.0](https://github.com/JSONPath-Plus/JSONPath/commit/6b2f1b4c234292c75912b790bf7e2d7339d4ccd3) but it could still be exploited using [different payloads](https://github.com/JSONPath-Plus/JSONPath/issues/226).
Added Reference Snyk https://github.com/JSONPath-Plus/JSONPath/commit/b70aa713553caf838a63bac923195a5bc541fd72 [No types assigned]
Added Reference Snyk https://github.com/JSONPath-Plus/JSONPath/issues/226 [No types assigned]

CVE Modified by Snyk 10/16/2024 5:15:03 AM

Action Type Old Value New Value
Added Reference Snyk https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-8185019 [No types assigned]

CVE Modified by CISA-ADP 10/11/2024 5:36:23 PM

Action Type Old Value New Value
Added CWE CISA-ADP CWE-94

New CVE Received from Snyk 10/11/2024 9:15:15 AM

Action Type Old Value New Value
Added Description Versions of the package jsonpath-plus before 10.0.0 are vulnerable to Remote Code Execution (RCE) due to improper input sanitization. An attacker can execute aribitrary code on the system by exploiting the unsafe default usage of vm in Node. **Note:** The unsafe behavior is still available after applying the fix but it is not turned on by default.
Added CVSS V3.1 Snyk AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Added CWE Snyk CWE-94
Added Reference Snyk https://github.com/JSONPath-Plus/JSONPath/commit/6b2f1b4c234292c75912b790bf7e2d7339d4ccd3 [No types assigned]
Added Reference Snyk https://security.snyk.io/vuln/SNYK-JS-JSONPATHPLUS-7945884 [No types assigned]