-
Notifications
You must be signed in to change notification settings - Fork 609
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
jsonpath-plus
Critical RCE in 4.0.0, need an update to 10.0.0 to fix it.
#4966
Comments
Reference: CVE-2024-21534 It's been 2 weeks with no response ? Rush team plz fix it asap |
Hello @iclanton , could I know when you will release the fix? I checked that in the latest version 5.140.0, this fix is not in it. |
It'll be in the next release of Rush. I can probably put out a patch today or tomorrow. |
5.140.1 is out with this change. |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Description:
Affected versions of this package are vulnerable to Remote Code Execution (RCE) due to improper input sanitization. An attacker can execute aribitrary code on the system by exploiting the unsafe default usage of vm in Node.
This package is present in
@rushstack/heft-config-file
package.jsonNote:
The unsafe behavior is still available after applying the fix but it is not turned on by default.
The text was updated successfully, but these errors were encountered: