This affects all versions of package json-pointer. A type confusion vulnerability can lead to a bypass of CVE-2020-7709 when the pointer components are arrays. References: https://snyk.io/vuln/SNYK-JS-JSONPOINTER-1577287 https://github.com/manuelstofer/json-pointer/blob/master/index.js#23L78
Upstream issue: https://github.com/manuelstofer/json-pointer/issues/35
This issue has been addressed in the following products: RHACS-3.70-RHEL-8 Via RHSA-2022:4880 https://access.redhat.com/errata/RHSA-2022:4880