Improper Control of Dynamically-Managed Code Resources in protobuf.js - CVE-2022-25878
Published: July 4, 2022
Vulnerability details
The vulnerability allows a remote attacker to modify data on the system.
The vulnerability exists due to Prototype Pollution error in protobufjs. A remote unauthenticated attacker can provide an untrusted user input to the util.setProperty or to the ReflectionObject.setParsedOption functions, and also by parse/load .proto files to modify data on the system.
Affected software
IBM Engineering Requirements Quality Assistant
Astronomer with IBM
Cloud Pak for Security (CP4S)
IBM Cloud Pak for Business Automation
Netcool Operations Insight
How to mitigate CVE-2022-25878
Astronomer with IBM - update to 1.0.1
Cloud Pak for Security (CP4S) - update to 1.10.7.0
Netcool Operations Insight - update to 1.6.6
External References
- https://github.com/protobufjs/protobuf.js/pull/1731
- https://github.com/protobufjs/protobuf.js/blob/d13d5d5688052e366aa2e9169f50dfca376b32cf/src/util.js%23L176-L197
- https://github.com/protobufjs/protobuf.js/commit/b5f1391dff5515894830a6570e6d73f5511b2e8f
- https://snyk.io/vuln/SNYK-JS-PROTOBUFJS-2441248
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-2841507
Related Security Bulletins
- Multiple vulnerabilities in IBM Cloud Pak for Business Automation
- Multiple vulnerabilities in Netcool Operations Insight
- Multiple vulnerabilities in IBM Engineering Requirements Quality Assistant On-Premises
- Multiple vulnerabilities in IBM Cloud Pak for Security (CP4S)
- Multiple vulnerabilities in Astronomer with IBM