PYSEC-2023-209

See a problem?
Import Source
https://github.com/pypa/advisory-database/blob/main/vulns/json-logic/PYSEC-2023-209.yaml
JSON Data
https://api.osv.dev/v1/vulns/PYSEC-2023-209
Withdrawn
2024-10-14T10:37:00Z
Published
2023-03-05T19:15:00Z
Modified
2023-10-20T16:31:18.877419Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

A vulnerability, which was classified as critical, has been found in json-logic-js 2.0.0. Affected by this issue is some unknown functionality of the file logic.js. The manipulation leads to command injection. Upgrading to version 2.0.1 is able to address this issue. The patch is identified as c1dd82f5b15d8a553bb7a0cfa841ab8a11a9c227. It is recommended to upgrade the affected component. VDB-222266 is the identifier assigned to this vulnerability.

References

Affected packages

PyPI / json-logic

Package

Affected ranges

Type
GIT
Repo
https://github.com/jwadhams/json-logic-js
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

0.*
0.6.2
0.6.3
0.7.0a0

Database specific

source
"https://github.com/pypa/advisory-database/blob/main/vulns/json-logic/PYSEC-2023-209.yaml"