REDHAT-BUG-2477104: High severity npm/protobufjs vulnerability
protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs generated JavaScript for toObject conversion could include an unsafe expression derived from a schema-controlled bytes field default value. A crafted descriptor with a non-string default value for a bytes field could cause attacker-controlled code to be emitted into the generated conversion function. This vulnerability is fixed in 7.5.6 and 8.0.2.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
protobufjsto a version that resolves this vulnerability.Fixed in 7.5.6 - Upgrade
Upgrade
protobufjsto a version that resolves this vulnerability.Fixed in 8.0.2
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2477104?
The severity of REDHAT-BUG-2477104 is classified as high with a score of 7.
How do I fix REDHAT-BUG-2477104?
To fix REDHAT-BUG-2477104, update protobufjs to version 7.5.6 or later.
What is the risk associated with REDHAT-BUG-2477104?
The risk associated with REDHAT-BUG-2477104 is rated at risk level 33.
What is the impact of REDHAT-BUG-2477104?
The impact of REDHAT-BUG-2477104 can allow for the generation of unsafe expressions in JavaScript functions.
Which versions of protobufjs are affected by REDHAT-BUG-2477104?
Versions prior to 7.5.6 and 8.0.2 of protobufjs are affected by REDHAT-BUG-2477104.