CVE-2020-7712

HIGH

json < 10.0.0 - OS Command Injection via parseLookup Function

Title source: llm
STIX 2.1

Description

This affects the package json before 10.0.0. It is possible to inject arbritary commands using the parseLookup function.

References (22)

Core 22
Core References
Exploit, Third Party Advisory x_refsource_misc
https://snyk.io/vuln/SNYK-JS-JSON-597481
Exploit, Third Party Advisory x_refsource_misc
https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-608931
Exploit, Third Party Advisory x_refsource_misc
https://github.com/trentm/json/issues/144
Patch, Third Party Advisory x_refsource_misc
https://github.com/trentm/json/pull/145
Patch, Third Party Advisory x_refsource_misc
https://www.oracle.com//security-alerts/cpujul2021.html
Patch, Third Party Advisory x_refsource_misc
https://www.oracle.com/security-alerts/cpujan2022.html
Patch, Third Party Advisory x_refsource_misc
https://www.oracle.com/security-alerts/cpujul2022.html

Scores

CVSS v3 7.2
EPSS 0.0373
EPSS Percentile 88.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-78
Status published
Products (8)
joyent/json < 10.0.0
npm/json 0 - 10.0.0npm
oracle/commerce_guided_search 11.3.2
oracle/financial_services_crime_and_compliance_management_studio 8.0.8.2.0
oracle/financial_services_crime_and_compliance_management_studio 8.0.8.3.0
oracle/financial_services_regulatory_reporting_with_agilereporter 8.0.9.6.3
oracle/timesten_in-memory_database < 21.1.1.1.0
org.webjars.npm/json 0Maven
Published Aug 30, 2020
Tracked Since Feb 18, 2026