Denial of Service in gRPC Core
CVE-2023-4785

7.5HIGH

Key Information:

Vendor
Google
Status
Vendor
CVE Published:
13 September 2023

Summary

A vulnerability exists in the TCP server of Google's gRPC, affecting versions starting from 1.23 on posix-compatible platforms, such as Linux. This flaw arises from inadequate error handling, enabling an attacker to execute a denial of service attack by establishing a large number of connections to the server. While the gRPC implementations in C++, Python, and Ruby are susceptible, the Java and Go versions remain unaffected. It is crucial for users of the impacted versions to implement appropriate safeguards to mitigate potential risks.

Affected Version(s)

gRPC Posix-compatible platforms 1.56.0 <= 1.56.1

gRPC Posix-compatible platforms 1.55.0 <= 1.55.2

gRPC Posix-compatible platforms 1.54.0 <= 154.2

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.