logo

Database

Lack of data validation In grafana

Description

A flaw was found in protobufjs. This vulnerability occurs because protobufjs, which compiles protobuf definitions into JavaScript (JS) functions, does not properly escape certain control characters in field names when generating JavaScript property accessors. A remote attacker could provide a specially crafted schema or JSON descriptor, causing the generated encode, decode, verify, or conversion functions to fail during compilation. This could lead to a denial of service (DoS) condition for applications using the affected protobufjs library.

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Component
Affected version
Patched versions