PYSEC-2017-101

Google gRPC before 2017-03-29 has an out-of-bounds write caused by a heap-based use-after-free related to the grpc_call_destroy function in core/lib/surface/call.c.Read More ...

Continue Reading

CVSS3 - CRITICAL

CVSS2 - HIGH

Denial Of Service (DoS)

github.com/andreimatei/grpc-go is vulnerable to denial of service (DoS) attacks. A malicious user can send an empty hpack string to the system and cause it to crash.Read More ...

Continue Reading
Cisco IOS XR Software Event Management Service gRPC Handling DoS (cisco-sa-20170503-ios-xr)

According to its self-reported version and configuration, the Cisco IOS XR software running on the remote device is affected by a denial of service vulnerability in the Event Management Service daemon ...

Continue Reading
Gitlab — multiple vulnerabilities

Gitlab reports: SSRF GCP access token disclosure Persistent XSS on issue details Diff formatter DoS in Sidekiq jobs Confidential information disclosure in events API endpoint validate_localhost functi ...

Continue Reading

CVSS3 - CRITICAL

CVSS2 - HIGH

FreeBSD : Gitlab — multiple vulnerabilities (065b3b72-c5ab-11e8-9ae2-001b217b3468)

Gitlab reports : SSRF GCP access token disclosure Persistent XSS on issue details Diff formatter DoS in Sidekiq jobs Confidential information disclosure in events API endpoint validate_localhost funct ...

Continue Reading
Happy graduation, Envoy!

Envoy, the new darling of the DevOps community, performs the role of a service and edge proxy. With advanced features such as timeouts, rate limiting, circuit breaking, load balancing, retries, stats, ...

Continue Reading
CVE-2018-16886

etcd versions 3.2.x before 3.2.26 and 3.3.x before 3.3.11 are vulnerable to an improper authentication issue when role-based access control (RBAC) is used and client-cert-auth is enabled. If an etcd c ...

Continue Reading

CVSS3 - HIGH

CVSS2 - MEDIUM

grpc/api_fuzzer: Incorrect-function-pointer-type in grpc_core::AresDnsResolver::StartResolvingLocked

Project: https://github.com/grpc/grpc.git Detailed report: https://oss-fuzz.com/testcase?key=5752853455437824 Project: grpc Fuzzer: libFuzzer_grpc_api_fuzzer Fuzz target binary: api_fuzzer Job Type: l ...

Continue Reading

Back to Main

Subscribe for the latest news: