Описание
The package grpc before 1.24.4; the package @grpc/grpc-js before 1.1.8 are vulnerable to Prototype Pollution via loadPackageDefinition.
Ссылки
- PatchThird Party Advisory
- PatchThird Party Advisory
- MitigationThird Party Advisory
- MitigationThird Party Advisory
- MitigationThird Party Advisory
- PatchThird Party Advisory
- PatchThird Party Advisory
- MitigationThird Party Advisory
- MitigationThird Party Advisory
- MitigationThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.1.8 (исключая)Версия до 1.24.2 (исключая)
Одно из
cpe:2.3:a:grpc:grpc:*:*:*:*:*:node.js:*:*
cpe:2.3:a:grpc:grpc:*:*:*:*:*:-:*:*
EPSS
Процентиль: 80%
0.01321
Низкий
7.5 High
CVSS3
9.8 Critical
CVSS3
5 Medium
CVSS2
Дефекты
CWE-1321
Связанные уязвимости
CVSS3: 7.5
redhat
больше 5 лет назад
The package grpc before 1.24.4; the package @grpc/grpc-js before 1.1.8 are vulnerable to Prototype Pollution via loadPackageDefinition.
EPSS
Процентиль: 80%
0.01321
Низкий
7.5 High
CVSS3
9.8 Critical
CVSS3
5 Medium
CVSS2
Дефекты
CWE-1321