ZeroHour

CVE-2020-7712

PoC ×3
CVSS 3.1
7.2 high
EPSS
3%p87
Published
()
Modified
Description

This affects the package json before 10.0.0. It is possible to inject arbritary commands using the parseLookup function.

Vendors
joyentoracle
Products
json, commerce guided search, financial services crime and compliance management studio, financial services regulatory reporting with agilereporter, timesten in-memory database
Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.