CVE Vulnerabilities

CVE-2023-4785

Published: Sep 13, 2023 | Modified: Sep 19, 2023
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
7.5 MODERATE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM

Lack of error handling in the TCP server in Googles gRPC starting version 1.23 on posix-compatible platforms (ex. Linux) allows an attacker to cause a denial of service by initiating a significant number of connections with the server. Note that gRPC C++ Python, and Ruby are affected, but gRPC Java, and Go are NOT affected. 

Affected Software

Name Vendor Start Version End Version
Grpc Grpc 1.23.0 (including) 1.53.2 (excluding)
Grpc Grpc 1.54.0 (including) 1.54.3 (excluding)
Grpc Grpc 1.55.0 (including) 1.55.3 (excluding)
Grpc Grpc 1.56.0 (including) 1.56.0 (including)
Grpc Ubuntu bionic *
Grpc Ubuntu lunar *
Grpc Ubuntu mantic *
Grpc Ubuntu trusty *
Grpc Ubuntu xenial *
Red Hat Satellite 6.14 for RHEL 8 RedHat rubygem-grpc-0:1.58.0-1.el8sat *

References