Six Proto6 Vulnerabilities in protobuf.js Expose Node.js Apps to RCE and DoS

Image for article Six Proto6 Vulnerabilities in protobuf.js Expose Node.js Apps to RCE and DoS
News Source : Internet

News Summary

  • Protobuf is a free and open-source, language-agnostic mechanism for serializing structured data.
  • It was originally developed and used internally by Google before it was made publicly available in 2008.
  • The identified vulnerabilities affect Node.js applications that use protobuf.js, Google Cloud client libraries, messaging frameworks like Baileys.
  • The following versions of the tool are vulnerable - Patches for the flaws are available inprotobufjs 7.5.6 and 8.0.2.
Cybersecurity researchers have flagged half a dozen vulnerabilities in protobuf.

Must read Articles