QID 983896
QID 983896: Nodejs (npm) Security Update for protobufjs (GHSA-762f-c2wg-m8c8)
Versions of `protobufjs` before 5.0.3 and 6.8.6 are vulnerable to denial of service when parsing crafted invalid *.proto files. ## Recommendation Update to version 5.0.3, 6.8.6 or later.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-762f-c2wg-m8c8 for updates pertaining to this vulnerability.
Vendor References
- GHSA-762f-c2wg-m8c8 -
github.com/advisories/GHSA-762f-c2wg-m8c8
CVEs related to QID 983896
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-762f-c2wg-m8c8 | protobufjs |
|