CVE-2020-7712
30.08.2020, 08:15
This affects the package json before 10.0.0. It is possible to inject arbritary commands using the parseLookup function.
Vendor | Product | Version |
---|---|---|
joyent | json | 𝑥 < 10.0.0 |
oracle | commerce_guided_search | 11.3.2 |
oracle | financial_services_crime_and_compliance_management_studio | 8.0.8.2.0 |
oracle | financial_services_crime_and_compliance_management_studio | 8.0.8.3.0 |
oracle | financial_services_regulatory_reporting_with_agilereporter | 8.0.9.6.3 |
oracle | timesten_in-memory_database | 𝑥 < 21.1.1.1.0 |
𝑥
= Vulnerable software versions
References