REDHAT-BUG-2477081: High severity protobufjs vulnerability
protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.8 and 8.2.0, protobufjs could recurse without a depth limit while expanding nested JSON descriptors through Root.fromJSON() and Namespace.addJSON(). A crafted JSON descriptor with deeply nested namespace definitions could cause the JavaScript call stack to be exhausted during descriptor loading. This vulnerability is fixed in 7.5.8 and 8.2.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
protobufjsto a version that resolves this vulnerability.Fixed in 7.5.8 - Upgrade
Upgrade
protobufjsto a version that resolves this vulnerability.Fixed in 8.2.0
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2477081?
The severity of REDHAT-BUG-2477081 is classified as high with a score of 7.
How do I fix REDHAT-BUG-2477081?
To fix REDHAT-BUG-2477081, upgrade to protobufjs version 7.5.8 or 8.2.0 or later.
What is the risk associated with REDHAT-BUG-2477081?
The risk associated with REDHAT-BUG-2477081 is rated at 33, indicating a significant security concern.
What vulnerabilities does REDHAT-BUG-2477081 address?
REDHAT-BUG-2477081 addresses a vulnerability in protobufjs that allows for unbounded recursion while processing nested JSON descriptors.
Which software is affected by REDHAT-BUG-2477081?
The software affected by REDHAT-BUG-2477081 is protobufjs, prior to versions 7.5.8 and 8.2.0.