SB20250227186 - IBM watsonx Orchestrate Cartridge for IBM Cloud Pak for Data update for jsonata-js JSONata



SB20250227186 - IBM watsonx Orchestrate Cartridge for IBM Cloud Pak for Data update for jsonata-js JSONata

Published: February 27, 2025

Security Bulletin ID SB20250227186
Severity
High
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Prototype pollution (CVE-ID: CVE-2024-27307)

The vulnerability allows a remote attacker to execute arbitrary JavaScript code.

The vulnerability exists due to malicious expression can use the transform operator to override properties on the `Object` constructor and prototype.. A remote attacker can pass specially crafted input to the application and perform prototype pollution, which can result in denial of service, remote code execution or other unexpected behavior in applications that evaluate user-provided JSONata expressions.


Remediation

Install update from vendor's website.