CVE-2024-27307
published 2024-03-06CVE-2024-27307: JSONata is a JSON query and transformation language. Starting in version 1.4.0 and prior to version 1.8.7 and 2.0.4, a malicious expression can use the…
PriorityP358critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.42%
71.7th percentile
JSONata is a JSON query and transformation language. Starting in version 1.4.0 and prior to version 1.8.7 and 2.0.4, a malicious expression can use the transform operator to override properties on the `Object` constructor and prototype. This may lead to denial of service, remote code execution or other unexpected behavior in applications that evaluate user-provided JSONata expressions. This issue has been fixed in JSONata versions 1.8.7 and 2.0.4. Applications that evaluate user-provided expressions should update ASAP to prevent exploitation. As a workaround, one may apply the patch manually.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| jsonata-js | jsonata | — | — |
| jsonata-js | jsonata | — | — |
| jsonata | jsonata | >= 1.4.0 < 1.8.7 | 1.8.7 |
| jsonata | jsonata | >= 1.4.0 < 1.8.7 | 1.8.7 |
| jsonata | jsonata | >= 2.0.0 < 2.0.4 | 2.0.4 |
| jsonata | jsonata | >= 2.0.0 < 2.0.4 | 2.0.4 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
JSONata expression can pollute the "Object" prototype
osv·2024-03-04
CVE-2024-27307 [CRITICAL] JSONata expression can pollute the "Object" prototype
JSONata expression can pollute the "Object" prototype
### Impact
In JSONata versions `>= 1.4.0, = 2.0.0, = 1.8.7` and `>= 2.0.4`. Applications that evaluate user-provided expressions should update ASAP to prevent exploitation. The following patch can be applied if updating is not possible.
```patch
--- a/src/jsonata.js
+++ b/src/jsonata.js
@@ -1293,6 +1293,13 @@ var jsonata = (function() {
}
for(var ii = 0; ii < matches.length; ii++) {
var match = matches[ii];
+ if (match && (match.isPrototypeOf(result) || match instanceof Object.constructor)) {
+ throw {
+ code: "D1010",
+ stack: (new Error()).stack,
+ position: expr.position
+ };
+ }
// evaluate the update value for each match
var update = await evaluate(expr.update, match, environment);
// update must be an object
@@ -1539,7 +1546,7
GHSA
JSONata expression can pollute the "Object" prototype
ghsa·2024-03-04
CVE-2024-27307 [CRITICAL] CWE-1321 JSONata expression can pollute the "Object" prototype
JSONata expression can pollute the "Object" prototype
### Impact
In JSONata versions `>= 1.4.0, = 2.0.0, = 1.8.7` and `>= 2.0.4`. Applications that evaluate user-provided expressions should update ASAP to prevent exploitation. The following patch can be applied if updating is not possible.
```patch
--- a/src/jsonata.js
+++ b/src/jsonata.js
@@ -1293,6 +1293,13 @@ var jsonata = (function() {
}
for(var ii = 0; ii < matches.length; ii++) {
var match = matches[ii];
+ if (match && (match.isPrototypeOf(result) || match instanceof Object.constructor)) {
+ throw {
+ code: "D1010",
+ stack: (new Error()).stack,
+ position: expr.position
+ };
+ }
// evaluate the update value for each match
var update = await evaluate(expr.update, match, environment);
// update must be an object
@@ -1539,7 +1546,7
Red Hat
jsonata: malicious expression can pollute the "Object" prototype
vendor_redhat·2024-03-06·CVSS 9.8
CVE-2024-27307 [CRITICAL] CWE-1321 jsonata: malicious expression can pollute the "Object" prototype
jsonata: malicious expression can pollute the "Object" prototype
JSONata is a JSON query and transformation language. Starting in version 1.4.0 and prior to version 1.8.7 and 2.0.4, a malicious expression can use the transform operator to override properties on the `Object` constructor and prototype. This may lead to denial of service, remote code execution or other unexpected behavior in applications that evaluate user-provided JSONata expressions. This issue has been fixed in JSONata versions 1.8.7 and 2.0.4. Applications that evaluate user-provided expressions should update ASAP to prevent exploitation. As a workaround, one may apply the patch manually.
A vulnerability was found in JSONata. A malicious expression can exploit the transform operator to override properties on the Object
No detection rules found.
No public exploits indexed.
https://github.com/jsonata-js/jsonata/commit/1d579dbe99c19fbe509f5ba2c6db7959b0d456d1https://github.com/jsonata-js/jsonata/commit/335d38f6278e96c908b24183f1c9c90afc8ae00chttps://github.com/jsonata-js/jsonata/commit/c907b5e517bb718015fcbd993d742ba6202f2be2https://github.com/jsonata-js/jsonata/releases/tag/v2.0.4https://github.com/jsonata-js/jsonata/security/advisories/GHSA-fqg8-vfv7-8fj8https://github.com/jsonata-js/jsonata/commit/1d579dbe99c19fbe509f5ba2c6db7959b0d456d1https://github.com/jsonata-js/jsonata/commit/335d38f6278e96c908b24183f1c9c90afc8ae00chttps://github.com/jsonata-js/jsonata/commit/c907b5e517bb718015fcbd993d742ba6202f2be2https://github.com/jsonata-js/jsonata/releases/tag/v2.0.4https://github.com/jsonata-js/jsonata/security/advisories/GHSA-fqg8-vfv7-8fj8
2024-03-06
Published