Lack of data validation In grafana
Description
A flaw was found in protobufjs. This vulnerability occurs because protobufjs, which compiles protobuf definitions into JavaScript (JS) functions, does not properly escape certain control characters in field names when generating JavaScript property accessors. A remote attacker could provide a specially crafted schema or JSON descriptor, causing the generated encode, decode, verify, or conversion functions to fail during compilation. This could lead to a denial of service (DoS) condition for applications using the affected protobufjs library.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
npm | 7.5.6, 8.0.2 | ||
rpm rhel8 | - | - |
Aliases
1. 2. 3. 4. 5.
References
1. 2. 3.