CVE-2020-7712: Command Injection
This affects the package json before 10.0.0. It is possible to inject arbritary commands using the parseLookup function.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is CVE-2020-7712?
CVE-2020-7712 is a vulnerability that affects the package json before version 10.0.0 and allows for arbitrary command injection using the parseLookup function.
What software is affected by CVE-2020-7712?
The software affected by CVE-2020-7712 includes org.webjars.npm:json, npm/json, Joyent Json, Oracle Commerce Guided Search, Oracle Financial Services Crime And Compliance Management Studio, Oracle TimesTen In-Memory Database.
What is the severity of CVE-2020-7712?
CVE-2020-7712 has a severity rating of 7.2, indicating a high severity vulnerability.
How can I fix CVE-2020-7712?
To fix CVE-2020-7712, update your package json to version 10.0.0 or later.
Where can I find more information about CVE-2020-7712?
You can find more information about CVE-2020-7712 on the NIST NVD website (https://nvd.nist.gov/vuln/detail/CVE-2020-7712) and on the GitHub repository for json (https://github.com/trentm/json/issues/144).