Intel

AIKIDO-2024-10043

@apidevtools/json-schema-ref-parser is vulnerable to Prototype Pollution

Prototype PollutionCVE-2024-29651 Published Apr 23, 2024

30

Low Risk

This Affects:

JS@apidevtools/json-schema-ref-parser
11.0.0 - 11.1.1
Fixed in 11.2.0
Are you affected? Scan for Free

TL;DR

A prototype pollution issue was silently patched in version 11.2.0 of @apidevtools/json-schema-ref-parser.

Who does this affect?

You are affected if you are using a version which is within vulnerability ranges and if you are using $RefParserOptions.

Background info

@apidevtools/json-schema-ref-parser is vulnerable to Prototype Pollution in versions 11.0.0 - 11.1.1.

How to fix this

Upgrade the @apidevtools/json-schema-ref-parser library to the patch version.