Description
This affects the package json-pointer before 0.6.1. Multiple reference of object using slash is supported.
Remediation
References
https://github.com/manuelstofer/json-pointer/pull/34/files
https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-598862
https://snyk.io/vuln/SNYK-JS-JSONPOINTER-596925
Related Vulnerabilities
CVE-2019-17495 Vulnerability in maven package org.webjars.npm:swagger-ui
CVE-2021-32859 Vulnerability in maven package org.webjars.npm:github-com-baremetrics-calendar
CVE-2022-36914 Vulnerability in maven package org.jenkins-ci.plugins:files-found-trigger
CVE-2023-37460 Vulnerability in maven package org.codehaus.plexus:plexus-archiver