Prototype pollution in protobuf.js - CVE-2023-36665

 

Prototype pollution in protobuf.js - CVE-2023-36665

Published: August 2, 2023


Vulnerability identifier: #VU78870
CSH Severity: Critical
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-36665
CWE-ID: CWE-1321
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary JavaScript code.

The vulnerability exists due to improper input validation. A remote attacker can pollute the prototype of Object.prototype by adding and overwriting its data and functions.


Affected software

protobuf.js
Astronomer with IBM
IBM Cloud Pak for Watson AIOps
Storage Ceph
QRadar Suite
IBM App Connect Enterprise
Voice Gateway
App Connect Enterprise Certified Container
IBM Maximo Application Suite

How to mitigate CVE-2023-36665

Cybersecurity Help is currently unaware of any official solution to address this vulnerability..

protobuf.js - update to 7.2.4
Astronomer with IBM - update to 1.0.1
QRadar Suite - update to 1.10.18.0
Voice Gateway - addressed in versions 1.0.8.7, 1.0.8.11
IBM Cloud Pak for Watson AIOps - update to 4.1.1
App Connect Enterprise Certified Container - addressed in versions 5.0.9, 9.1.0
Storage Ceph - update to 7.1
IBM Maximo Application Suite - addressed in versions 8.9.9, 8.10.4

External References

Related Security Bulletins