Intel

AIKIDO-2024-10345

jsonpath-plus is vulnerable to Remote Code Execution (RCE)

Remote Code Execution (RCE)CVE-2024-21534 Published Oct 16, 2024

90

Critical Risk

This Affects:

jsjsonpath-plus
0.1.0 - 10.1.0
Fixed in 10.2.0
Are you affected? Scan for Free

TL;DR

Affected versions of the package remain vulnerable to Remote Code Execution (RCE). CVE-2024-21534 was not fully addressed in version 10.0.0, leaving the possibility of RCE for certain inputs.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

jsonpath-plus is vulnerable to Remote Code Execution (RCE) in versions 0.1.0 - 10.1.0.

How to fix this

Upgrade the jsonpath-plus library to the patch version.