CVE-2024-21534
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Oct 11, 2024
Updated: Nov 18, 2024
CWE ID 94
Summary
CVE-2024-21534 is a Remote Code Execution (RCE) vulnerability affecting all versions of the jsonpath-plus package. The issue stems from improper input sanitization, allowing attackers to execute arbitrary code on the system through the unsafe default usage of Node's vm module. Previous attempts to address this vulnerability in versions 10.0.0 to 10.1.0 were not successful, as attackers could still exploit it using various payloads.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.