
Summary gRPC is used by DataStage on Cloud Pak for Data as part of service communication. Vulnerability Details CVEID:CVE-2020-7768 DESCRIPTION: The package grpc before 1.24.4; the package @grpc/grpc-js before 1.1.8 are vulnerable to Prototype Pollution via loadPackageDefinition. CWE:CWE-1321: Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') CVSS Source: IBM X-Force CVSS Base score: 7.5 CVSS Vector:(CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) Affected Products and Versions Affected Product(s)| Version(s) —|— DataStage on Cloud Pak for Data| 5.2 Remediation/Fixes IBM strongly recommends addressing the vulnerability now by upgrading to the latest 5.2 patch. Product(s)| Version(s) number and/or range| Remediation/Fix/Instructions —|—|— DataStage on Cloud Pak for Data| 5.2| Upgrade to the latest 5.2 patch by following these instructions. Workarounds and Mitigations…Read More
References
Back to Main