9.8

CVE-2020-17479

Exploit
jpv (aka Json Pattern Validator) before 2.2.2 does not properly validate input, as demonstrated by a corrupted array.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Json Pattern Validator ProjectJson Pattern Validator SwPlatformnode.js Version < 2.2.2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.46% 0.824
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

https://www.npmjs.com/package/jpv
Third Party Advisory
Product
https://blog.sonatype.com/cve-2020-17479
Third Party Advisory
Exploit
https://github.com/manvel-khnkoyan/jpv/commit/e3eec1215caa8d5c560f5e88d0943422831927d6
Patch
Third Party Advisory
https://github.com/manvel-khnkoyan/jpv/issues/10
Third Party Advisory
Exploit