Back

CRITICAL

jsonpath-plus: Remote Code Execution in jsonpath-plus via Improper Input Sanitization

Published Oct 11, 2024

Description

All versions of the package jsonpath-plus are vulnerable to Remote Code Execution (RCE) due to improper input sanitization. An attacker can execute aribitrary code on the system by exploiting the unsafe default usage of vm in Node. **Note:** There were several attempts to fix it in versions [10.0.0-10.1.0](https://github.com/JSONPath-Plus/JSONPath/compare/v9.0.0...v10.1.0) but it could still be exploited using [different payloads](https://github.com/JSONPath-Plus/JSONPath/issues/226).

Affected products

Remediation

Red Hat statement

Red Hat's initial impact rating of critical has been downgraded to low. While the vulnerable code is technically still present within Red Hat products, there are no code paths in affected products which allow exploitation. As such, the impact to Red Hat products is low. Each of the products listed have multiple components where a fixed build could occur. This distinction does not matter for users as only one build needs fixed for the product. Additionally, in Red Hat OpenShift AI, jsonpath-plus is a dependency of a direct dependency and is never loaded, as the direct dependency's feature that requires jsonpath-plus is not used.

Red Hat mitigation

Red Hat Product Security recommends updating the vulnerable software to the latest version.

Metrics

Weaknesses (1)

References (14)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner snyk
Published Oct 11, 2024
Updated Nov 18, 2024
Reserved Dec 22, 2023
CISA Vulnrichment
Updated Oct 11, 2024
NVD
Status Deferred
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Oct 11, 2024
GHSA-PPPG-CPFQ-H7WR