Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

protobufjs Prototype Pollution vulnerability #7122

Closed
sandeep-reddy-u opened this issue May 7, 2024 · 2 comments · Fixed by #7189 · May be fixed by #7127
Closed

protobufjs Prototype Pollution vulnerability #7122

sandeep-reddy-u opened this issue May 7, 2024 · 2 comments · Fixed by #7189 · May be fixed by #7127
Assignees

Comments

@sandeep-reddy-u
Copy link

Project https://github.com/firebase/firebase-tools has dependency on @google-cloud/pubsub package, which has a critical security vulnerability.

Severity: critical
Title: protobufjs Prototype Pollution vulnerability
Package: protobufjs
Patched in protobufjs version: >=7.2.5
Path: firebase-tools > @google-cloud/pubsub > google-gax > protobufjs
More info: https://www.npmjs.com/advisories/1096964

This issue has been fixed in the latest versions of @google-cloud/pubsub package. But firebase-tools project is still using @google-cloud/pubsub version 3.x.x even in its latest release.

@aalej
Copy link
Contributor

aalej commented May 7, 2024

Hey @sandeep-reddy-u, thanks for reporting this. Let me discuss this with our engineering team to see what we can do to address the vulnerability issue.

@sandeep-reddy-u
Copy link
Author

Hi @aalej and Team,

Thanks for picking this issue and I see you already made progress which is Great News!

I would like to know when can we expect a release with this fix. If we don't have exact release date already, tentative timeline will also help.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging a pull request may close this issue.

2 participants