CVE-2021-4329 is a critical command injection vulnerability affecting json-logic-js version 2.0.0, specifically within an unknown functionality of the logic.js file. This vulnerability carries a CVSS score of 9.8, indicating a severe impact with high confidentiality, integrity, and availability compromise, and can be exploited remotely without user interaction or authentication. While no active exploits, Metasploit modules, or public exploit code are currently available, and community discussion is minimal, upgrading to json-logic-js version 2.0.1 is strongly recommended to remediate this flaw.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.0.0CPE matchmatch criteria | cpe:2.3:a:json-logic-js_project:json-logic-js:2.0.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.