Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
In jpv (aka Json Pattern Validator) before 2.1.1, compareCommon() can be bypassed because certain internal attributes can be overwritten via a conflicting name, as demonstrated by 'constructor': {'name':'Array'}. This affects validate(). Hence, a crafted payload can overwrite this builtin attribute to manipulate the type detection result.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Json Pattern Validator 授权问题漏洞
Vulnerability Description
Json Pattern Validator(JPV)是一款JSON模式验证器。 JPV 2.1.1之前版本中存在安全漏洞。攻击者可借助特制的payload利用该漏洞操作类型检测的结果。
CVSS Information
N/A
Vulnerability Type
N/A