Remote Code Execution Vulnerability in jsonpath-plus Prior to 10.0.0
CVE-2024-21534
Key Information:
- Vendor
Json Path Plus
- Vendor
- CVE Published:
- 11 October 2024
Badges
What is CVE-2024-21534?
The jsonpath-plus package is exposed to a Remote Code Execution (RCE) vulnerability due to inadequate input sanitization practices. This vulnerability allows an attacker to execute arbitrary code on the affected system, particularly taking advantage of the unsafe default usage of the Node.js vm module. Although there were multiple remediation efforts in versions from 10.0.0 to 10.1.0, the flaw persists due to the ability to exploit the vulnerability utilizing different payloads. This raises significant security concerns for users relying on jsonpath-plus in their applications.
Affected Version(s)
jsonpath-plus 0 < 10.0.7
org.webjars.npm:jsonpath-plus 0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
EPSS Score
45% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved