Junglewise Threat Intelligence

CVE-2024-21534: JSONPath Plus remote code execution via unsafe vm usage

CVE-2024-21534 · Severity: low · CVSS 3.1 · Published 2024-10-11

Technologies: JSONPath-Plus Jsonpath. Vendors: Maven, npm.

Executive brief

JSONPath Plus is a JavaScript library for querying JSON data using JSONPath expressions. Due to improper input sanitization in its vm module usage, attackers can execute arbitrary code on systems running vulnerable versions by crafting malicious path expressions. This allows complete system compromise including data theft, service disruption, and lateral movement.

Technical details

The vulnerability is a code injection flaw (CWE-94) in jsonpath-plus versions before 10.2.0 that stems from unsafe use of Node.js's vm module without proper input sanitization. An attacker can craft specially crafted JSONPath expressions as the `path` parameter to execute arbitrary JavaScript code with the privileges of the Node.js process. The attack requires network access to an application using the library but no authentication or user interaction. Multiple patch attempts (versions 10.0.0-10.1.0) were bypassed with alternative payloads, requiring fixes in version 10.2.0 or later.

Affected products

  • JSONPath-Plus JSONPath before 10.2.0

Timeline

  • 2024-10-11: disclosed: CVE-2024-21534 published
  • 2024-10-16: other: Additional RCE bypass demonstrated in version 10.0.0
  • 2024-10-14: patched: Fix released in version 10.2.0

References

Related threats