Prototype pollution in protobuf.js - CVE-2023-36665
Published: August 2, 2023
Vulnerability identifier: #VU78870
CSH Severity: Critical
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-36665
CWE-ID: CWE-1321
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary JavaScript code.
The vulnerability exists due to improper input validation. A remote attacker can pollute the prototype of Object.prototype by adding and overwriting its data and functions.
Affected software
protobuf.js
Astronomer with IBM
IBM Cloud Pak for Watson AIOps
Storage Ceph
QRadar Suite
IBM App Connect Enterprise
Voice Gateway
App Connect Enterprise Certified Container
IBM Maximo Application Suite
Astronomer with IBM
IBM Cloud Pak for Watson AIOps
Storage Ceph
QRadar Suite
IBM App Connect Enterprise
Voice Gateway
App Connect Enterprise Certified Container
IBM Maximo Application Suite
How to mitigate CVE-2023-36665
Cybersecurity Help is currently unaware of any official solution to address this vulnerability..
protobuf.js - update to 7.2.4
Astronomer with IBM - update to 1.0.1
QRadar Suite - update to 1.10.18.0
Voice Gateway - addressed in versions 1.0.8.7, 1.0.8.11
IBM Cloud Pak for Watson AIOps - update to 4.1.1
App Connect Enterprise Certified Container - addressed in versions 5.0.9, 9.1.0
Storage Ceph - update to 7.1
IBM Maximo Application Suite - addressed in versions 8.9.9, 8.10.4
Astronomer with IBM - update to 1.0.1
QRadar Suite - update to 1.10.18.0
Voice Gateway - addressed in versions 1.0.8.7, 1.0.8.11
IBM Cloud Pak for Watson AIOps - update to 4.1.1
App Connect Enterprise Certified Container - addressed in versions 5.0.9, 9.1.0
Storage Ceph - update to 7.1
IBM Maximo Application Suite - addressed in versions 8.9.9, 8.10.4
External References
- https://github.com/protobufjs/protobuf.js/commit/e66379f451b0393c27d87b37fa7d271619e16b0d
- https://github.com/protobufjs/protobuf.js/compare/protobufjs-v7.2.3...protobufjs-v7.2.4
- https://github.com/protobufjs/protobuf.js/pull/1899
- https://www.code-intelligence.com/blog/cve-protobufjs-prototype-pollution-cve-2023-36665
- https://github.com/protobufjs/protobuf.js/releases/tag/protobufjs-v7.2.4
Related Security Bulletins
- Multiple vulnerabilities in IBM Cloud Pak for Watson AIOps
- Prototype pollution in IBM App Connect Enterprise Certified Container
- Multiple vulnerabilities in IBM Voice Gateway
- Multiple vulnerabilities in IBM App Connect Enterprise
- Prototype pollution in IBM Maximo Application Suite
- Multiple vulnerabilities in IBM QRadar Suite Software
- Prototype pollution in IBM Storage Ceph
- Multiple vulnerabilities in Astronomer with IBM