CacheControl / CacheControl/json-rules-engine

High severity security flaw in JSONPath Plus allows Remote Code Execution - please update dependency

Aberta
#413 4 comentários 0 reações 0 responsáveis Ver no GitHub
Linguagem predominante
JavaScript
Estrelas
3.1k
Forks
507
Métricas de merge de PRs
Nenhum PR com merge em 30d

Descrição

High severity security flaw in JSONPath Plus allows Remote Code Execution - please update dependency

![Image](https://github.com/user-attachments/assets/d063a602-6b3b-4eab-b101-d5d96dc0c6c6)

Guia de contribuição

Nenhum guia de contribuição indexado para este repositório

Direção de pesquisa

Start by locating the JSONPath Plus dependency in the repository's dependency manifests and checking which version is currently used. Update it to a release that addresses the reported remote-code-execution flaw, then run the project's existing test suite to verify that the rules engine still works.

Escrita pelo modelo de indexação a partir do texto da issue.

Avaliação

Stack de tecnologia
javascript
Domínio
security
Tipo de issue
Bug
Dificuldade
2/5
Tempo estimado
1-3 horas
Status de atividade
Estagnada
Clareza
Precisa de esclarecimento
Facilidade para iniciantes
25/100

Receba novas issues na sua caixa de entrada

Um resumo curto de issues do GitHub para quem está começando.