DirectorySecurity Advisories
Sign In
Security Advisories

CGA-9c79-2q9x-78w6

Published

Last updated

https://images.chainguard.dev/security/CGA-9c79-2q9x-78w6
Package

kibana-8

Latest Update
Under investigation
Aliases
  • CVE-2023-36665
  • GHSA-h755-8qp9-cq85

Severity

9.8

Critical

CVSS V3

Summary

protobufjs Prototype Pollution vulnerability

Description

protobuf.js (aka protobufjs) 6.10.0 until 6.11.4 and 7.0.0 until 7.2.4 allows Prototype Pollution, a different vulnerability than CVE-2022-25878. A user-controlled protobuf message can be used by an attacker to pollute the prototype of Object.prototype by adding and overwriting its data and functions. Exploitation can involve: (1) using the function parse to parse protobuf messages on the fly, (2) loading .proto files by using load/loadSync functions, or (3) providing untrusted input to the functions ReflectionObject.setParsedOption and util.setProperty. NOTE: this CVE Record is about Object.constructor.prototype.<new-property> = ...; whereas CVE-2022-25878 was about Object.__proto__.<new-property> = ...; instead.

References

Updates


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2024 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard Images