漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Starcounter-Jack JSON-Patch prototype pollution
Vulnerability Description
A vulnerability has been found in Starcounter-Jack JSON-Patch up to 3.1.0 and classified as problematic. This vulnerability affects unknown code. The manipulation leads to improperly controlled modification of object prototype attributes ('prototype pollution'). The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 3.1.1 is able to address this issue. The name of the patch is 7ad6af41eabb2d799f698740a91284d762c955c9. It is recommended to upgrade the affected component. VDB-216778 is the identifier assigned to this vulnerability.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Vulnerability Type
CWE-1321
Vulnerability Title
JSON-Patch 安全漏洞
Vulnerability Description
JSON-Patch是Joachim Wester个人开发者的一个 JSON 补丁标准(RFC 6902)的精简和平均 Javascript 实现。 JSON-Patch 3.1.1之前版本存在安全漏洞,该漏洞源于会导致对象原型属性的修改控制不当,存在原型污染。
CVSS Information
N/A
Vulnerability Type
N/A