Description
protobufjs is vulnerable to ReDoS when parsing crafted invalid .proto files.
Remediation
References
https://hackerone.com/reports/319576
Related Vulnerabilities
CVE-2018-3722 Vulnerability in maven package org.webjars.npm:merge-deep
CVE-2021-23358 Vulnerability in maven package org.webjars.npm:underscore
CVE-2022-36897 Vulnerability in maven package com.compuware.jenkins:compuware-xpediter-code-coverage
CVE-2021-23451 Vulnerability in npm package otp-generator
CVE-2022-35697 Vulnerability in maven package com.adobe.cq:core.wcm.components.core