cbcvebase.
CVE-2020-7712
published 2020-08-30

CVE-2020-7712: This affects the package json before 10.0.0. It is possible to inject arbritary commands using the parseLookup function.

high7.2CVSS 3.1
AVNACLPRHUINSUCHIHAH
This affects the package json before 10.0.0. It is possible to inject arbritary commands using the parseLookup function.

Affected

8 ranges
VendorProductVersion rangeFixed in
joyentjson< 10.0.010.0.0
joyentjson>= 0 < 10.0.010.0.0
joyentjson>= unspecified < 10.0.010.0.0
oraclecommerce_guided_search
oraclefinancial_services_crime_and_compliance_management_studio
oraclefinancial_services_crime_and_compliance_management_studio
oraclefinancial_services_regulatory_reporting_with_agilereporter
oracletimesten_in-memory_database< 21.1.1.1.021.1.1.1.0