Skip to content

Vulnerabilies in @apollo/protobufjs (dependency of apollo-reporting-protobuf) #6835

@belegur

Description

@belegur

Hello, reporting here some security issues that we are receiving in the aws inspector.

The last version (1.2.4) of the @apollo/protobufjs fork has a lot of vulnerabilities in its cli package-lock.json.
This package-lock.json is distributed with the package, so we get all the security warnings when the inspector scans the file.

Hoisted from apollo-server-core#apollo-reporting-protobuf#@apollo#protobufjs

All these vulnerabilities have been fixed in the original protobufjs repository, but the fork is not keeping in sync.

Related vulnerabilities:
CVE-2021-44906
IN1-JS-LODASH-1040724
CVE-2022-21680
CVE-2021-23358

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions