Fedora 38 : grpc (2023-15b3e80753)

The remote Fedora 38 host has a package installed that is affected by multiple vulnerabilities as referenced in the FEDORA-2023-15b3e80753 advisory. - gRPC contains a vulnerability whereby a client ...

Continue Reading
Fedora 37 : grpc (2023-6cad6e5003)

The remote Fedora 37 host has a package installed that is affected by multiple vulnerabilities as referenced in the FEDORA-2023-6cad6e5003 advisory. - gRPC contains a vulnerability whereby a client ...

Continue Reading
Connection Termination

grpc is vulnerable to Connection Termination. An attacker can terminate the connection between a HTTP2 proxy and the gRPC server by providing a `-bin` suffixed headers, which leads to a base64 encodin ...

Continue Reading

CVSS3 - MEDIUM

CVSS2 - MEDIUM

Amazon Linux 2 : ecs-service-connect-agent (ALASECS-2023-003)

The version of ecs-service-connect-agent installed on the remote host is prior to v1.25.4.0-1. It is, therefore, affected by multiple vulnerabilities as referenced in the ALAS2ECS-2023-003 advisory. ...

Continue Reading
Denial Of Service (DoS)

grpc is vulnerable to Denial Of Service (DoS). The vulnerability exists due to improper header validation which allows an attacker to send headers such as `te: x (x != trailers)`, `scheme: x (x != htt ...

Continue Reading

CVSS3 - HIGH

CVSS2 - MEDIUM

gRPC connection termination issue

gRPC contains a vulnerability whereby a client can cause a termination of connection between a HTTP2 proxy and a gRPC server: a base64 encoding error for `-bin` suffixed headers will result in a disco ...

Continue Reading
gRPC Reachable Assertion issue

There exists an vulnerability causing an abort() to be called in gRPC. The following headers cause gRPC's C++ implementation to abort() when called via http2: te: x (x != trailers) :scheme: x (x != ht ...

Continue Reading
Connection confusion in gRPC

When gRPC HTTP2 stack raised a header size exceeded error, it skipped parsing the rest of the HPACK frame. This caused any HPACK table mutations to also be skipped, resulting in a desynchronization of ...

Continue Reading

Back to Main

Subscribe for the latest news: