Prototype pollution in gRPC - CVE-2020-7768
Published: January 31, 2023
Vulnerability identifier: #VU71696
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-7768
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources in the loadPackageDefinition component. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.
Affected software
gRPC
DataStage on Cloud Pak for Data
Voice Gateway
Cloud Pak for Security (CP4S)
DataStage on Cloud Pak for Data
Voice Gateway
Cloud Pak for Security (CP4S)
How to mitigate CVE-2020-7768
Install update from vendor's website.
gRPC - addressed in versions 1.1.8, 1.24.4
Voice Gateway - addressed in versions 1.0.8.2, 1.0.8.6
Cloud Pak for Security (CP4S) - update to 1.10.14.0
Voice Gateway - addressed in versions 1.0.8.2, 1.0.8.6
Cloud Pak for Security (CP4S) - update to 1.10.14.0