QID 981869
QID 981869: Nodejs (npm) Security Update for @grpc/grpc-js (GHSA-pp75-xfpw-37g9)
"The package grpc before 1.24.4 and the package @grpc/grpc-js before 1.1.8 are vulnerable to Prototype Pollution via loadPackageDefinition."
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-pp75-xfpw-37g9 for updates pertaining to this vulnerability.
Vendor References
- GHSA-pp75-xfpw-37g9 -
github.com/advisories/GHSA-pp75-xfpw-37g9
CVEs related to QID 981869
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-pp75-xfpw-37g9 | @grpc/grpc-js |
|
|
| GHSA-pp75-xfpw-37g9 | grpc |
|