First published: Wed Nov 11 2020(Updated: )
The package grpc before 1.24.4; the package @grpc/grpc-js before 1.1.8 are vulnerable to Prototype Pollution via loadPackageDefinition.
Credit: report@snyk.io
Affected Software | Affected Version | How to fix |
---|---|---|
Grpc Grpc | <1.1.8 | |
Grpc Grpc | <1.24.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-7768.
The severity of CVE-2020-7768 is critical with a CVSS score of 9.8.
CVE-2020-7768 is a vulnerability in the package grpc before 1.24.4 and the package @grpc/grpc-js before 1.1.8 that allows prototype pollution via loadPackageDefinition.
The package grpc before 1.24.4 and the package @grpc/grpc-js before 1.1.8 are affected by CVE-2020-7768.
Update the package grpc to version 1.24.4 or later, or update the package @grpc/grpc-js to version 1.1.8 or later to fix CVE-2020-7768.