First published: Mon Oct 05 2020(Updated: )
This affects the package json-pointer before 0.6.1. Multiple reference of object using slash is supported.
Credit: report@snyk.io
Affected Software | Affected Version | How to fix |
---|---|---|
Smallpdf | <0.6.1 | |
maven/org.webjars.npm:json-pointer | <0.6.1 | 0.6.1 |
npm/json-pointer | <0.6.1 | 0.6.1 |
Manuelstofer Json-pointer | <0.6.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-7709 is considered to have a moderate severity level based on its potential impact and exploitability.
To fix CVE-2020-7709, upgrade the json-pointer package to version 0.6.1 or later.
CVE-2020-7709 affects the json-pointer package versions prior to 0.6.1 in both Smallpdf and Manuelstofer implementations.
CVE-2020-7709 is a vulnerability related to improper handling of object references using slashes in the json-pointer package.
As of now, there have been no reported exploits specifically targeting CVE-2020-7709 in the wild.