Lucene search

K
nodejsAnonymousNODEJS:1707
HistoryMay 10, 2021 - 7:18 p.m.

Prototype Pollution

2021-05-1019:18:00
Anonymous
www.npmjs.com
57
grpc
@grpc/grpc-js
prototype pollution
vulnerability
upgrade
cve-2020-7768
github advisory

EPSS

0.005

Percentile

77.6%

Overview

“The package grpc before 1.24.4 and the package @grpc/grpc-js before 1.1.8 are vulnerable to Prototype Pollution via loadPackageDefinition.”

Recommendation

Upgrade to version 1.1.8 or later

References