CVE-2020-7768: Prototype Pollution
Published Nov 11, 2020
·Updated
The package grpc before 1.24.4; the package @grpc/grpc-js before 1.1.8 are vulnerable to Prototype Pollution via loadPackageDefinition.
Affected Software
2 affected components
gRPC Grpc Node.js<1.1.8
gRPC gRPC<1.24.2
Remediation
Patch Available
Patch Available
Event History
Nov 11, 2020
CVE Published
via MITRE·10:20 AM
Data Sourced
via MITRE·10:20 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2020-7768.
2
What is the severity of CVE-2020-7768?
The severity of CVE-2020-7768 is critical with a CVSS score of 9.8.
3
What is the description of CVE-2020-7768?
CVE-2020-7768 is a vulnerability in the package grpc before 1.24.4 and the package @grpc/grpc-js before 1.1.8 that allows prototype pollution via loadPackageDefinition.
4
Which software versions are affected by CVE-2020-7768?
The package grpc before 1.24.4 and the package @grpc/grpc-js before 1.1.8 are affected by CVE-2020-7768.
5
How can I fix CVE-2020-7768?
Update the package grpc to version 1.24.4 or later, or update the package @grpc/grpc-js to version 1.1.8 or later to fix CVE-2020-7768.