CVE Vulnerabilities

CVE-2023-4785

Uncaught Exception

Published: Sep 13, 2023 | Modified: Jan 12, 2026
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
7.5 MODERATE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Lack of error handling in the TCP server in Googles gRPC starting version 1.23 on posix-compatible platforms (ex. Linux) allows an attacker to cause a denial of service by initiating a significant number of connections with the server. Note that gRPC C++ Python, and Ruby are affected, but gRPC Java, and Go are NOT affected.

Weakness

An exception is thrown from a function, but it is not caught.

Affected Software

NameVendorStart VersionEnd Version
GrpcGrpc1.23.0 (including)1.53.2 (excluding)
GrpcGrpc1.54.0 (including)1.54.3 (excluding)
GrpcGrpc1.55.0 (including)1.55.3 (excluding)
GrpcGrpc1.56.0 (including)1.56.0 (including)
Red Hat Satellite 6.14 for RHEL 8RedHatrubygem-grpc-0:1.58.0-1.el8sat*
GrpcUbuntubionic*
GrpcUbuntufocal*
GrpcUbuntulunar*
GrpcUbuntumantic*
GrpcUbuntuoracular*
GrpcUbuntuplucky*
GrpcUbuntutrusty*
GrpcUbuntuxenial*

References