CVE-2023-32732

gRPC contains a vulnerability whereby a client can cause a termination of connection between a HTTP2 proxy and a gRPC server: a base64 encoding error for `-bin` suffixed headers will result in a disco ...

Continue Reading

CVSS3 - MEDIUM

CVSS2 - MEDIUM

CVE-2023-35942

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to versions 1.27.0, 1.26.4, 1.25.9, 1.24.10, and 1.23.12, gRPC access loggers using listener's global scope ...

Continue Reading

CVSS3 - MEDIUM

CVSS2 - MEDIUM

Denial Of Service (DoS)

gRPC is vulnerable to Denial Of Service (DoS). The vulnerability exists because the file descriptor is not properly handled, which leads to the termination of the connection between a proxy and a back ...

Continue Reading
(RHSA-2023:4623) Important: Red Hat OpenShift Service Mesh 2.2.9 security update

Red Hat OpenShift Service Mesh is Red Hat's distribution of the Istio service mesh project, tailored for installation into an OpenShift Container Platform installation. Security Fix(es): * envoy: Clie ...

Continue Reading

CVSS3 - CRITICAL

CVSS2 - HIGH

(RHSA-2023:4624) Important: Red Hat OpenShift Service Mesh Containers for 2.3.6 security update

Red Hat OpenShift Service Mesh is Red Hat's distribution of the Istio service mesh project, tailored for installation into an on-premise OpenShift Container Platform installation. Security Fix(es): * ...

Continue Reading

CVSS3 - CRITICAL

CVSS2 - HIGH

Moderate Photon OS Security Update – PHSA-2023-5.0-0068

Updates of ['grpc'] packages of Photon OS have been released.Read More ...

Continue Reading

CVSS3 - MEDIUM

CVSS2 - MEDIUM

Denial Of Service (DoS)

github.com/envoyproxy/envoy is vulnerable to Denial of Service (DoS) attacks. When the listener is exhausted, `gRPC` access logs utilizing its global scope may result in a `use-after-free`, which allo ...

Continue Reading
Security Bulletin: IBM Watson Discovery Cartridge for IBM Cloud Pak for Data affected by vulnerability in gRPC

## Summary IBM Watson Discovery Cartridge for IBM Cloud Pak for Data contains a vulnerable version of gRPC. ## Vulnerability Details ** CVEID: **[CVE-2023-32732]() ** DESCRIPTION: **gRPC is vulnerable ...

Continue Reading

CVSS3 - HIGH

CVSS2 - MEDIUM

Back to Main

Subscribe for the latest news: