Lack of data validation In grafana
Description
A flaw was found in protobufjs, a library used to compile protobuf definitions into JavaScript functions. A remote attacker could exploit this vulnerability by providing a crafted descriptor that includes a non-string default value for a bytes field. This could lead to the generation of an unsafe expression within the toObject conversion function, ultimately allowing the attacker to execute arbitrary code.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
npm | 7.5.6, 8.0.2 | ||
rpm rhel9 | - | - | |
rpm rhel10 | 0:1.1.1-1.el10_2 |
Aliases
1. 2. 3. 4. 5.
References
1. 2. 3.