HIGH · 7.2

CVE-2020-7712

This affects the package json before 10.0.0. It is possible to inject arbritary commands using the parseLookup function.

Vulnerability Description

This affects the package json before 10.0.0. It is possible to inject arbritary commands using the parseLookup function.

CVSS Score

7.2

HIGH

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
JoyentJson< 10.0.0
OracleCommerce Guided Search11.3.2
OracleFinancial Services Crime And Compliance Management Studio8.0.8.2.0
OracleFinancial Services Regulatory Reporting With Agilereporter8.0.9.6.3
OracleTimesten In-Memory Database< 21.1.1.1.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2020-7712?

CVE-2020-7712 is a vulnerability with a CVSS score of 7.2 (HIGH). This affects the package json before 10.0.0. It is possible to inject arbritary commands using the parseLookup function.

How severe is CVE-2020-7712?

CVE-2020-7712 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2020-7712?

Check the references section above for vendor advisories and patch information. Affected products include: Joyent Json, Oracle Commerce Guided Search, Oracle Financial Services Crime And Compliance Management Studio, Oracle Financial Services Regulatory Reporting With Agilereporter, Oracle Timesten In-Memory Database.