Junglewise Threat Intelligence

CVE-2020-7712: trentm json command injection in parseLookup

CVE-2020-7712 · Severity: low · CVSS 3.1 · Published 2021-05-06

Vendors: Maven, npm.

Executive brief

The 'json' library, a tool used for processing and looking up data within JSON structures, is vulnerable to command injection. An attacker with the ability to provide specially crafted lookup strings can execute arbitrary operating system commands on the server or machine running the library. This could lead to full system compromise, unauthorized data access, or service disruption.

Technical details

The 'json' package (trentm/json) is vulnerable to OS command injection due to the use of the 'eval()' function when processing bracketed lookup strings. Specifically, the 'parseLookup' function fails to properly sanitize input, allowing an attacker to break out of the intended logic and execute arbitrary JavaScript, which can then be used to run system commands via 'child_process'. While the CVSS vector indicates high privileges (PR:H) may be required depending on the implementation, the vulnerability itself is a classic CWE-78 flaw. The issue was resolved in version 10.0.0 by restricting the supported syntax for bracketed parts of lookup strings to avoid the need for evaluation.

Affected products

  • trentm json < 10.0.0
  • org.webjars.npm json <= 9.0.6

Timeline

  • 2020-08-06: disclosed: Issue reported on GitHub
  • 2020-08-28: patched: Fix merged in pull request 145
  • 2020-08-30: advisory: NVD published CVE-2020-7712

References