Denial of Service in gRPC Core
CVE-2023-4785
7.5HIGH
Summary
A vulnerability exists in the TCP server of Google's gRPC, affecting versions starting from 1.23 on posix-compatible platforms, such as Linux. This flaw arises from inadequate error handling, enabling an attacker to execute a denial of service attack by establishing a large number of connections to the server. While the gRPC implementations in C++, Python, and Ruby are susceptible, the Java and Go versions remain unaffected. It is crucial for users of the impacted versions to implement appropriate safeguards to mitigate potential risks.
Affected Version(s)
gRPC Posix-compatible platforms 1.56.0 <= 1.56.1
gRPC Posix-compatible platforms 1.55.0 <= 1.55.2
gRPC Posix-compatible platforms 1.54.0 <= 154.2
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved