Executive brief
json-pointer is a JavaScript library used to access and manipulate JSON objects via pointer references. A prototype pollution vulnerability allows an attacker to inject malicious properties into JavaScript objects, potentially leading to unexpected application behavior, data manipulation, or denial of service depending on how the affected application uses the library.
Technical details
The vulnerability is a prototype pollution flaw (CWE-1321) affecting json-pointer versions before 0.6.1. The library fails to properly filter dangerous properties such as "prototype", "proto", and "constructor" when processing multiple slash-separated object references. An attacker can craft malicious JSON pointer references that pollute the prototype chain of JavaScript objects. This is a network-accessible vulnerability requiring no user authentication or interaction. Successful exploitation can result in confidentiality loss, integrity compromise, and availability impact. The fix was merged in pull request #34 and released in version 0.6.1.
Affected products
- json-pointer json-pointer before 0.6.1
Timeline
- 2020-10-05: disclosed: Published on NVD
- 2020-09-24: patched: Fix merged in PR #34; version 0.6.1 released
- 2021-05-10: advisory: GHSA advisory published