CVE Vulnerabilities

CVE-2023-4785

Uncaught Exception

Published: Sep 13, 2023 | Modified: Nov 21, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
7.5 MODERATE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM

Lack of error handling in the TCP server in Googles gRPC starting version 1.23 on posix-compatible platforms (ex. Linux) allows an attacker to cause a denial of service by initiating a significant number of connections with the server. Note that gRPC C++ Python, and Ruby are affected, but gRPC Java, and Go are NOT affected. 

Weakness

An exception is thrown from a function, but it is not caught.

Affected Software

Name Vendor Start Version End Version
Grpc Grpc 1.23.0 (including) 1.53.2 (excluding)
Grpc Grpc 1.54.0 (including) 1.54.3 (excluding)
Grpc Grpc 1.55.0 (including) 1.55.3 (excluding)
Grpc Grpc 1.56.0 (including) 1.56.0 (including)
Red Hat Satellite 6.14 for RHEL 8 RedHat rubygem-grpc-0:1.58.0-1.el8sat *
Grpc Ubuntu bionic *
Grpc Ubuntu lunar *
Grpc Ubuntu mantic *
Grpc Ubuntu trusty *
Grpc Ubuntu xenial *

References