CVE-2023-36665 vunerablity in protobufjs >= 6.10.0, < 7.2.4 #879
Labels
api: cloudprofiler
Issues related to the googleapis/cloud-profiler-nodejs API.
priority: p2
Moderately-important priority. Fix may not be included in next release.
type: bug
Error or flaw in code with unintended results or allowing sub-optimal usage patterns.
Link to vulnerability report: GHSA-h755-8qp9-cq85
@google-cloud/profiler
usespprof
3.2.0, which in turn usesprotobufjs
~7.0.0The vulnerability has been patched in
protobufjs
7.2.4, butpprof
still needs to be patched to use the newer versionThere's an issue here to track the
protobufjs
upgrade withinpprof
: google/pprof-nodejs#256The
pprof
version used by@google-cloud/profiler
locked to 3.2.0, so it'll need to be bumped when theprotobufjs
dependency is upgradedEnvironment details
@google-cloud/profiler
version: 5.0.4Steps to reproduce
@google-cloud/profiler
The text was updated successfully, but these errors were encountered: