|
Bugzilla – Full Text Bug Listing |
| Summary: | VUL-0: CVE-2023-36665: nodejs-electron: protobufjs: prototype pollution using user-controlled protobuf message | ||
|---|---|---|---|
| Product: | [openSUSE] openSUSE Tumbleweed | Reporter: | Carlos López <carlos.lopez> |
| Component: | Security | Assignee: | Bruno Pitrus <brunopitrus> |
| Status: | RESOLVED INVALID | QA Contact: | Security Team bot <security-team> |
| Severity: | Normal | ||
| Priority: | P3 - Medium | CC: | security-team |
| Version: | Current | ||
| Target Milestone: | --- | ||
| Hardware: | Other | ||
| OS: | Other | ||
| URL: | https://smash.suse.de/issue/371250/ | ||
| Whiteboard: | |||
| Found By: | --- | Services Priority: | |
| Business Priority: | Blocker: | --- | |
| Marketing QA Status: | --- | IT Deployment: | --- |
|
Description
Carlos López
2023-07-06 08:06:00 UTC
openSUSE:Factory/nodejs-electron embeds protobufjs 6.10.2 There are no instances of the offending code in the electorn tarball.
There are two mentions of protobufjs 6.10.2 inside third_party/perfetto/{infra/perfetto.dev,ui}/package-lock.json but these directories are not used in chromium/electron.
|