[🐸 Frogbot] Update version of google.golang.org/protobuf to 1.33.0 #22
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
📦 Vulnerable Dependencies
✍️ Summary
Medium
google.golang.org/protobuf:v1.31.0
github.com/containerd/containerd:v1.7.11
github.com/jfrog/jfrog-cli-core/v2:v2.48.1
github.com/jfrog/jfrog-cli-security:v1.0.3
github.com/spf13/afero:v1.11.0
github.com/spf13/viper:v1.18.2
google.golang.org/genproto/googleapis/rpc:v0.0.0-20231120223509-83a465c0220f
🔬 Research Details
Description:
The protojson.Unmarshal function can enter an infinite loop when unmarshaling certain forms of invalid JSON. This condition can occur when unmarshaling into a message which contains a google.protobuf.Any value, or when the UnmarshalOptions.DiscardUnknown option is set.
🐸 JFrog Frogbot