jmespath.rb (aka JMESPath for Ruby) before 1.6.1 uses JSON.load in a situation where JSON.parse is preferable.
References
Configurations
Information
Published : 2022-06-06 22:15
Updated : 2022-06-17 13:15
NVD link : CVE-2022-32511
Mitre link : CVE-2022-32511
JSON object : View
Products Affected
jmespath_project
- jmespath
CWE
