Improper Control of Dynamically-Managed Code Resources in protobuf.js - CVE-2022-25878

 

Improper Control of Dynamically-Managed Code Resources in protobuf.js - CVE-2022-25878

Published: July 4, 2022


Vulnerability identifier: #VU64865
CSH Severity: High
CVSS v4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-25878
CWE-ID: CWE-913
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to modify data on the system.

The vulnerability exists due to Prototype Pollution error in protobufjs. A remote unauthenticated attacker can provide an untrusted user input to the util.setProperty or to the ReflectionObject.setParsedOption functions, and also by parse/load .proto files to modify data on the system.


Affected software

protobuf.js
IBM Engineering Requirements Quality Assistant
Astronomer with IBM
Cloud Pak for Security (CP4S)
IBM Cloud Pak for Business Automation
Netcool Operations Insight

How to mitigate CVE-2022-25878

Install update from vendor's website.

protobuf.js - update to 6.11.3
Astronomer with IBM - update to 1.0.1
Cloud Pak for Security (CP4S) - update to 1.10.7.0
Netcool Operations Insight - update to 1.6.6

External References

Related Security Bulletins