CVE Vulnerabilities

CVE-2023-4785

Published: Sep 13, 2023 | Modified: Sep 19, 2023
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Lack of error handling in the TCP server in Googles gRPC starting version 1.23 on posix-compatible platforms (ex. Linux) allows an attacker to cause a denial of service by initiating a significant number of connections with the server. Note that gRPC C++ Python, and Ruby are affected, but gRPC Java, and Go are NOT affected. 

Affected Software

Name Vendor Start Version End Version
Grpc Grpc 1.23.0 (including) 1.53.2 (excluding)
Grpc Grpc 1.54.0 (including) 1.54.3 (excluding)
Grpc Grpc 1.55.0 (including) 1.55.3 (excluding)
Grpc Grpc 1.56.0 (including) 1.56.0 (including)

References