Executive brief
json-logic-js is a JavaScript library used to evaluate logic rules expressed as JSON data. A command injection vulnerability in version 2.0.0 allows an attacker to execute arbitrary code by manipulating the operations object. This could enable complete system compromise, including unauthorized access to sensitive data and disruption of services.
Technical details
The vulnerability is a command injection flaw (CWE-77) in the logic.js file of json-logic-js that allows arbitrary code execution through the operations object. An attacker can exploit this by crafting malicious JSON logic that injects commands, which are then executed without proper sanitization. The attack requires no authentication or user interaction and is remotely exploitable over the network. Exploitation allows an attacker to achieve complete code execution with full system privileges. The vulnerability is fixed in version 2.0.1 (patch c1dd82f5b15d8a553bb7a0cfa841ab8a11a9c227).
Affected products
- jwadhams json-logic-js all versions up to 2.0.0
Timeline
- 2023-03-05: disclosed
- 2021-03-30: patched: Fix merged in PR #98
- 2023-03-07: advisory: GitHub security review