This CPE summary could be partial or incomplete. Please contact us for a detailed listing.

Summary

Detail
Vendor Deep-Parse-Json Project First view 2022-11-03
Product Deep-Parse-Json Last view 2022-11-03
Version 1.0.2 Type Application
Update *  
Edition *  
Language *  
Sofware Edition *  
Target Software node.js  
Target Hardware *  
Other *  
 
CPE Product cpe:2.3:a:deep-parse-json_project:deep-parse-json

Activity : Overall

Related : CVE

  Date Alert Description
5.3 2022-11-03 CVE-2022-42743

deep-parse-json version 1.0.2 allows an external attacker to edit or add new properties to an object. This is possible because the application does not correctly validate the incoming JSON keys, thus allowing the '__proto__' property to be edited.