@grpc/grps-js implements the core functionality of gRPC purely in JavaScript, without a C++ addon. Prior to 1.9.16, 1.10.12, 1.11.4, 1.12.7, 1.13.5, and 1.14.4, an invalid incoming compressed message can cause a client or server process that uses @grpc/grpc-js to crash. This issue is fixed in versions 1.9.16, 1.10.12, 1.11.4, 1.12.7, 1.13.5, and 1.14.4.
An exception is thrown from a function, but it is not caught.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Red Hat Developer Hub 1.10 | RedHat | rhdh/red-hat-developer-hub-backstage-plugin-orchestrator-backend:1785332825 | * |
| Red Hat Developer Hub 1.10 | RedHat | rhdh/red-hat-developer-hub-backstage-plugin-orchestrator-backend-module-loki:1785332668 | * |
| Red Hat Developer Hub 1.10 | RedHat | rhdh/red-hat-developer-hub-backstage-plugin-scaffolder-backend-module-orchestrator:1785332694 | * |