Description
This affects the package json-pointer before 0.6.1. Multiple reference of object using slash is supported.
Remediation
References
https://github.com/manuelstofer/json-pointer/pull/34/files
https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-598862
https://snyk.io/vuln/SNYK-JS-JSONPOINTER-596925
Related Vulnerabilities
CVE-2015-3253 Vulnerability in maven package org.codehaus.groovy:groovy-all
CVE-2021-22112 Vulnerability in maven package org.springframework.security:spring-security-core
CVE-2011-1088 Vulnerability in maven package org.apache.tomcat:tomcat-catalina
CVE-2018-1000620 Vulnerability in maven package org.webjars.npm:cryptiles