CVE-2023-36665 detected on BlueXP connector when using BlueXP Backup and Recovery
Applies to
- BlueXP
- Connector VM
- BlueXP Backup & Recovery (also known as Cloud Backup Service)
Issue
- The vulnerability below is detected on the BlueXP connector VM when using BlueXP Backup & Recovery :
CVE-2023-36665
The library protobufjs version 7.2.4 was detected in NPM library manager located at /opt/netapp/cbs/server/node_modules/protobufjs/package.json and is vulnerable to CVE-2023-36665, which exists in versions >= 7.0.0, < 7.2.5.
The vulnerability was found in the Github Security Advisory with vendor severity: Critical (NVD severity: Critical).
This vulnerability has a known exploit available. Source: Code Intelligence.
The vulnerability can be remediated by updating the library to version 7.2.5 or higher, using npm update protobufjs
- The BlueXP connector VM is running on RHEL 7.x OS
