gRPC connection termination issue

gRPC contains a vulnerability whereby a client can cause a termination of connection between a HTTP2 proxy and a gRPC server: a base64 encoding error for `-bin` suffixed headers will result in a disco ...

Continue Reading

CVSS3 - MEDIUM

CVSS2 - MEDIUM

gRPC Reachable Assertion issue

There exists an vulnerability causing an abort() to be called in gRPC.  The following headers cause gRPC's C++ implementation to abort() when called via http2: te: x (x != trailers) :scheme: x (x ! ...

Continue Reading

CVSS3 - HIGH

CVSS2 - MEDIUM

gRPC connection termination issue

gRPC contains a vulnerability whereby a client can cause a termination of connection between a HTTP2 proxy and a gRPC server: a base64 encoding error for `-bin` suffixed headers will result in a disco ...

Continue Reading

CVSS3 - MEDIUM

CVSS2 - MEDIUM

gRPC Reachable Assertion issue

There exists an vulnerability causing an abort() to be called in gRPC.  The following headers cause gRPC's C++ implementation to abort() when called via http2: te: x (x != trailers) :scheme: x (x ! ...

Continue Reading

CVSS3 - HIGH

CVSS2 - MEDIUM

Security Bulletin: IBM Watson Assistant for IBM Cloud Pak for Data is vulnerable to Envoy security bypass ( CVE-2023-27488)

## Summary Potential Enyoy security bypass vulnerability ( CVE-2022-25881) has been identified that may affect IBM Watson Assistant for IBM Cloud Pak for Data. Refer to details for additional informat ...

Continue Reading

CVSS3 - CRITICAL

CVSS2 - HIGH

Stripe: Local applications from user’s computer can listen for webhooks via insecure gRPC server from stripe-cli

The stripe daemon command from the stripe-cli exposes a local gRPC server that does not require authentication and allows any local application to execute remote procedures. One of the procedures is L ...

Continue Reading
Improper Authentication

etcd versions 3.2.x before 3.2.26 and 3.3.x before 3.3.11 is vulnerable to an improper authentication issue when role-based access control (RBAC) is used and client-cert-auth is enabled. If an etcd cl ...

Continue Reading

CVSS3 - HIGH

CVSS2 - MEDIUM

grpc: Bad-cast to const std::__1::__less *_start

Project: https://github.com/grpc/grpc.git Detailed report: https://oss-fuzz.com/testcase?key=5138174202347520 Project: grpc Fuzzer: libFuzzer_grpc_uri_fuzzer_test Fuzz target binary: uri_fuzzer_test J ...

Continue Reading

Back to Main

Subscribe for the latest news: