CVE-2023-36665: Critical severity Protobufjs Project Protobufjs Node.js vulnerability
"protobuf.js (aka protobufjs) 6.10.0 through 7.x before 7.2.5 allows Prototype Pollution, a different vulnerability than CVE-2022-25878. A user-controlled protobuf message can be used by an attacker to pollute the prototype of Object.prototype by adding and overwriting its data and functions. Exploitation can involve: (1) using the function parse to parse protobuf messages on the fly, (2) loading .proto files by using load/loadSync functions, or (3) providing untrusted input to the functions ReflectionObject.setParsedOption and util.setProperty.
Other sources
protobuf.js (aka protobufjs) 6.10.0 until 6.11.4 and 7.0.0 until 7.2.4 allows Prototype Pollution, a different vulnerability than CVE-2022-25878. A user-controlled protobuf message can be used by an attacker to pollute the prototype of Object.prototype by adding and overwriting its data and functions. Exploitation can involve: (1) using the function parse to parse protobuf messages on the fly, (2) loading .proto files by using load/loadSync functions, or (3) providing untrusted input to the functions ReflectionObject.setParsedOption and util.setProperty. NOTE: this CVE Record is about Object.constructor.prototype.<new-property> = ...; whereas CVE-2022-25878 was about Object.proto.<new-property> = ...; instead.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/protobufjsto a version that resolves this vulnerability.Fixed in 7.2.5 - Upgrade
Upgrade
npm/protobufjsto a version that resolves this vulnerability.Fixed in 6.11.4
Event History
Frequently Asked Questions
What is the severity of CVE-2023-36665?
CVE-2023-36665 has a severity rating that indicates a potential risk of prototype pollution.
How do I fix CVE-2023-36665?
To mitigate CVE-2023-36665, upgrade to protobuf.js version 7.2.5 or 6.11.4.
What systems are affected by CVE-2023-36665?
CVE-2023-36665 affects protobuf.js versions from 6.10.0 to 7.x before 7.2.5.
What type of vulnerability is CVE-2023-36665?
CVE-2023-36665 is classified as a prototype pollution vulnerability.
Can CVE-2023-36665 be exploited remotely?
Yes, an attacker could potentially exploit CVE-2023-36665 remotely if they can send a user-controlled protobuf message.