Описание
protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.6.5 and 8.6.6, protobufjs parsed option names by advancing through schema tokens until reaching an = token without checking for end of input, so a crafted .proto schema that opens an option declaration and ends prematurely can cause parse, Root.load, or Root.loadSync to loop indefinitely. This issue is fixed in versions 7.6.5 and 8.6.6.
Ссылки
- Patch
- Patch
- Issue TrackingPatch
- ProductRelease Notes
- ProductRelease Notes
- MitigationVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 7.6.5 (исключая)Версия от 8.0.0 (включая) до 8.6.6 (исключая)
Одно из
cpe:2.3:a:protobufjs_project:protobufjs:*:*:*:*:*:node.js:*:*
cpe:2.3:a:protobufjs_project:protobufjs:*:*:*:*:*:node.js:*:*
EPSS
Процентиль: 30%
0.0037
Низкий
5.3 Medium
CVSS3
7.5 High
CVSS3
Дефекты
CWE-835
Связанные уязвимости
CVSS3: 5.3
debian
26 дней назад
protobufjs compiles protobuf definitions into JavaScript (JS) function ...
EPSS
Процентиль: 30%
0.0037
Низкий
5.3 Medium
CVSS3
7.5 High
CVSS3
Дефекты
CWE-835