使用BlueXP备份和恢复时、在BlueXP连接器上检测到CVE-2023-36665
适用场景
- BlueXP
- Connector VM
- BlueXP备份和恢复(也称为Cloud Backup Service)
问题描述
- 使用BlueXP备份和恢复时、在BlueXP Connector VM上检测到以下漏洞 :
CVE-2023-36665
The library protobufjs version 7.2.4 was detected in NPM library manager located at /opt/netapp/cbs/server/node_modules/protobufjs/package.json and is vulnerable to CVE-2023-36665, which exists in versions >= 7.0.0, < 7.2.5.
The vulnerability was found in the Github Security Advisory with vendor severity: Critical (NVD severity: Critical).
This vulnerability has a known exploit available. Source: Code Intelligence.
The vulnerability can be remediated by updating the library to version 7.2.5 or higher, using npm update protobufjs
- BlueXP Connector VM正在RHEL 7.x操作系统上运行