[MAVEN:GHSA-9HXF-PPJV-W6RQ] gRPC connection termination issue
Severity
Moderate
Affected Packages
3
Fixed Packages
3
CVEs
1
gRPC contains a vulnerability whereby a client can cause a termination of connection between a HTTP2 proxy and a gRPC server: a base64 encoding error for -bin
suffixed headers will result in a disconnection by the gRPC server, but is typically allowed by HTTP2 proxies. We recommend upgrading beyond the commit in https://github.com/grpc/grpc/pull/32309.
Package | Affected Version |
---|---|
pkg:maven/io.grpc/grpc-protobuf | < 1.53.0 |
pkg:maven/grpcio | < 1.53.0 |
pkg:maven/grpc | < 1.53.0 |
Package | Fixed Version |
---|---|
pkg:maven/io.grpc/grpc-protobuf | = 1.53.0 |
pkg:maven/grpcio | = 1.53.0 |
pkg:maven/grpc | = 1.53.0 |
- ID
- MAVEN:GHSA-9HXF-PPJV-W6RQ
- Severity
- moderate
- URL
- https://github.com/advisories/GHSA-9hxf-ppjv-w6rq
- Published
-
2023-07-06T21:15:08
(14 months ago) - Modified
-
2023-11-11T05:06:16
(10 months ago) - Rights
- Maven Security Team
- Other Advisories
Type | Package URL | Namespace | Name / Product | Version | Distribution / Platform | Arch | Patch / Fix |
---|---|---|---|---|---|---|---|
Affected | pkg:maven/io.grpc/grpc-protobuf | io.grpc | grpc-protobuf | < 1.53.0 | |||
Fixed | pkg:maven/io.grpc/grpc-protobuf | io.grpc | grpc-protobuf | = 1.53.0 | |||
Affected | pkg:maven/grpcio | grpcio | < 1.53.0 | ||||
Fixed | pkg:maven/grpcio | grpcio | = 1.53.0 | ||||
Affected | pkg:maven/grpc | grpc | < 1.53.0 | ||||
Fixed | pkg:maven/grpc | grpc | = 1.53.0 |
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | Exploits | PoC | Pubblication Date | Modification Date |
---|---|---|---|---|---|---|---|---|---|---|---|
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | PoC | Pubblication Date | Modification Date |