The package grpc before 1.24.4; the package @grpc/grpc-js before 1.1.8 are vulnerable to Prototype Pollution via loadPackageDefinition.
QA Contact: (none) => securityComponent: RPM Packages => SecurityCVE: (none) => CVE-2020-7768
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-7768 Upstream patches: https://github.com/grpc/grpc-node/pull/1605 https://github.com/grpc/grpc-node/pull/1606
Status comment: (none) => Patches available from upstreamAssignee: bugsquad => geiger.david68210Summary: grpc security issue CVE-2020-7768 => grpc new security issue CVE-2020-7768Severity: normal => major
We haven't the package "grpc-node", so we are not affected!
Indeed it looks like the affected code isn't in the package.
Status: NEW => RESOLVEDStatus comment: Patches available from upstream => (none)Resolution: (none) => INVALID