Lucene search

K
prionPRIOn knowledge basePRION:CVE-2024-27307
HistoryMar 06, 2024 - 8:15 p.m.

Remote code execution

2024-03-0620:15:00
PRIOn knowledge base
www.prio-n.com
8
jsonata
json query
transformation
malicious expression
override properties
denial of service
applications
update
nvd

9.7 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

15.5%

JSONata is a JSON query and transformation language. Starting in version 1.4.0 and prior to version 1.8.7 and 2.0.4, a malicious expression can use the transform operator to override properties on the Object constructor and prototype. This may lead to denial of service, remote code execution or other unexpected behavior in applications that evaluate user-provided JSONata expressions. This issue has been fixed in JSONata versions 1.8.7 and 2.0.4. Applications that evaluate user-provided expressions should update ASAP to prevent exploitation. As a workaround, one may apply the patch manually.

9.7 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

15.5%