Prototype pollution in JSONata - CVE-2024-27307
Published: April 9, 2024
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary JavaScript code.
The vulnerability exists due to malicious expression can use the transform operator to override properties on the `Object` constructor and prototype.. A remote attacker can pass specially crafted input to the application and perform prototype pollution, which can result in denial of service, remote code execution or other unexpected behavior in applications that evaluate user-provided JSONata expressions.
Affected software
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data
Maximo Application Suite - IoT Component
IBM Edge Application Manager
App Connect Enterprise Certified Container
IBM App Connect Enterprise
How to mitigate CVE-2024-27307
App Connect Enterprise Certified Container - addressed in versions 5.0.16, 11.4.0
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data - update to 5.1.1
Maximo Application Suite - IoT Component - addressed in versions 8.7.15, 8.8.11, 9.0.1
IBM App Connect Enterprise - update to 12.0.11.3
External References
- https://github.com/jsonata-js/jsonata/security/advisories/GHSA-fqg8-vfv7-8fj8
- https://github.com/jsonata-js/jsonata/commit/1d579dbe99c19fbe509f5ba2c6db7959b0d456d1
- https://github.com/jsonata-js/jsonata/commit/335d38f6278e96c908b24183f1c9c90afc8ae00c
- https://github.com/jsonata-js/jsonata/commit/c907b5e517bb718015fcbd993d742ba6202f2be2
- https://github.com/jsonata-js/jsonata/releases/tag/v2.0.4
Related Security Bulletins
- Prototype pollution in IBM App Connect Enterprise Certified Container
- Multiple vulnerabilities in IBM App Connect Enterprise
- Multiple vulnerabilities in IBM Edge Application Manager
- Multiple vulnerabilities in IBM Maximo Application Suite - IoT Component
- IBM watsonx Orchestrate Cartridge for IBM Cloud Pak for Data update for jsonata-js JSONata