CVE Vulnerabilities

CVE-2023-32732

Expected Behavior Violation

Published: Jun 09, 2023 | Modified: Nov 21, 2024
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
CVSS 2.x
RedHat/V2
RedHat/V3
5.3 MODERATE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Ubuntu
MEDIUM

gRPC contains a vulnerability whereby a client can cause a termination of connection between a HTTP2 proxy and a gRPC server: a base64 encoding error for -bin suffixed headers will result in a disconnection by the gRPC server, but is typically allowed by HTTP2 proxies. We recommend upgrading beyond the commit inĀ  https://github.com/grpc/grpc/pull/32309 https://www.google.com/url

Weakness

A feature, API, or function does not perform according to its specification.

Affected Software

Name Vendor Start Version End Version
Grpc Grpc * 1.53.0 (excluding)
Grpc Ubuntu bionic *
Grpc Ubuntu kinetic *
Grpc Ubuntu lunar *
Grpc Ubuntu mantic *
Grpc Ubuntu trusty *
Grpc Ubuntu upstream *
Grpc Ubuntu xenial *

References