UbuntuUpdates.org

Package "node-json5"

Name: node-json5

Description:

JSON for the ES5 era

Latest version: 0.5.1-3ubuntu0.1
Release: focal (20.04)
Level: updates
Repository: universe
Homepage: https://json5.org/

Links


Download "node-json5"


Other versions of "node-json5" in Focal

Repository Area Version
base universe 0.5.1-3
security universe 0.5.1-3ubuntu0.1

Changelog

Version: 0.5.1-3ubuntu0.1 2024-04-30 11:06:56 UTC

  node-json5 (0.5.1-3ubuntu0.1) focal-security; urgency=medium

  * SECURITY UPDATE: Prototype pollution in object returned by JSON5.parse
    - debian/patches/cve-2022-46175.diff: use Object.defineProperty instead of
      direct property assignment to stop __proto__ from being treated specially
      in lib/json5.js; unit test in test/testproto.js.
    - CVE-2022-46175

 -- Luci Stanescu <email address hidden> Thu, 25 Apr 2024 18:19:31 +0300

CVE-2022-46175 JSON5 is an extension to the popular JSON file format that aims to be easier to write and maintain by hand (e.g. for config files). The `parse` metho



About   -   Send Feedback to @ubuntu_updates