Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

JSONPath Plus Remote Code Execution (RCE) Vulnerability #248

Closed
thienscmon opened this issue Oct 15, 2024 · 3 comments
Closed

JSONPath Plus Remote Code Execution (RCE) Vulnerability #248

thienscmon opened this issue Oct 15, 2024 · 3 comments

Comments

@thienscmon
Copy link

jsonpath-plus  <10.0.0
Severity: critical
JSONPath Plus Remote Code Execution (RCE) Vulnerability - https://github.com/advisories/GHSA-pppg-cpfq-h7wr
fix available via `npm audit fix --force`
Will install [email protected], which is a breaking change
node_modules/jsonpath-plus
  redis-om  >=0.4.0-beta.1
  Depends on vulnerable versions of jsonpath-plus
  node_modules/redis-om

2 critical severity vulnerabilities
@dongshunyao
Copy link
Contributor

I also encountered this issue. It caused the CI/CD pipeline to fail and blocked my work.

I have created a pull request to fix it: #249.

@guyroyse Could you please review and approve it? That way we can continue working. Thanks!

@guyroyse
Copy link
Contributor

PR #249 from @dongshunyao has been merge and I pushed the new version to NPM. Y'all should be good to go.

@guyroyse
Copy link
Contributor

Let me know if you run into any problems. Thanks again!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants