Description
jpv (aka Json Pattern Validator) before 2.2.2 does not properly validate input, as demonstrated by a corrupted array.
Remediation
References
https://blog.sonatype.com/cve-2020-17479
https://github.com/manvel-khnkoyan/jpv/commit/e3eec1215caa8d5c560f5e88d0943422831927d6
https://github.com/manvel-khnkoyan/jpv/issues/10
https://www.npmjs.com/package/jpv
Related Vulnerabilities
CVE-2019-9737 Vulnerability in maven package org.webjars.bowergithub.pandao:editor.md
CVE-2021-32684 Vulnerability in npm package magento-scripts
CVE-2023-49486 Vulnerability in maven package com.jfinal:jfinal
CVE-2023-34468 Vulnerability in maven package org.apache.nifi:nifi-dbcp-base
CVE-2021-23631 Vulnerability in npm package convert-svg-core