Six Proto6 Vulnerabilities in protobuf.js Expose Node.js Apps to RCE and DoS
News Source : Internet
News Summary
- Protobuf is a free and open-source, language-agnostic mechanism for serializing structured data.
- It was originally developed and used internally by Google before it was made publicly available in 2008.
- The identified vulnerabilities affect Node.js applications that use protobuf.js, Google Cloud client libraries, messaging frameworks like Baileys.
- The following versions of the tool are vulnerable - Patches for the flaws are available inprotobufjs 7.5.6 and 8.0.2.
Cybersecurity researchers have flagged half a dozen vulnerabilities in protobuf.
Never miss a story from us, subscribe to our newsletter