MidnightBSD

Advisories for grpc

CVE-2017-7860 HIGH

Google gRPC before 2017-02-22 has an out-of-bounds write caused by a heap-based buffer overflow related to the parse_unix function in core/ext/client_channel/parse_address.c.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-787,

Products Affected

Vendor Product Version
grpc grpc *
CVE-2017-7861 HIGH

Google gRPC before 2017-02-22 has an out-of-bounds write related to the gpr_free function in core/lib/support/alloc.c.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-787,

Products Affected

Vendor Product Version
grpc grpc *
CVE-2017-8359 HIGH

Google gRPC before 2017-03-29 has an out-of-bounds write caused by a heap-based use-after-free related to the grpc_call_destroy function in core/lib/surface/call.c.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-787,

Products Affected

Vendor Product Version
grpc grpc *
CVE-2017-9431 HIGH

Google gRPC before 2017-04-05 has an out-of-bounds write caused by a heap-based buffer overflow related to core/lib/iomgr/error.c.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-787,

Products Affected

Vendor Product Version
grpc grpc *
CVE-2020-7768 MEDIUM

The package grpc before 1.24.4; the package @grpc/grpc-js before 1.1.8 are vulnerable to Prototype Pollution via loadPackageDefinition.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-1321,

Products Affected

Vendor Product Version
grpc grpc *
CVE-2023-1428

There exists an vulnerability causing an abort() to be called in gRPC.  The following headers cause gRPC's C++ implementation to abort() when called via http2: te: x (x != trailers) :scheme: x (x != http, https) grpclb_client_stats: x (x == anything) On top of sending one of those headers, a later header must be sent that gets the total header size past 8KB. We recommend upgrading past git commit 2485fa94bd8a723e5c977d55a3ce10b301b437f8 or v1.53 and above.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
cve-coordination@google.com 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H 3.9 3.6

Products Affected

Vendor Product Version
grpc grpc *
CVE-2023-32731

When gRPC HTTP2 stack raised a header size exceeded error, it skipped parsing the rest of the HPACK frame. This caused any HPACK table mutations to also be skipped, resulting in a desynchronization of HPACK tables between sender and receiver. If leveraged, say, between a proxy and a backend, this could lead to requests from the proxy being interpreted as containing headers from different proxy clients - leading to an information leak that can be used for privilege escalation or data exfiltration. We recommend upgrading beyond the commit contained in  https://github.com/grpc/grpc/pull/33005 https://github.com/grpc/grpc/pull/33005

CVSS 3.x

Source Score Severity Vector Exploitability Impact
cve-coordination@google.com 7.4 HIGH CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H 2.2 5.2

Products Affected

Vendor Product Version
grpc grpc *
CVE-2023-32732

gRPC contains a vulnerability whereby a client can cause a termination of connection between a HTTP2 proxy and a gRPC server: a base64 encoding error for `-bin` suffixed headers will result in a disconnection by the gRPC server, but is typically allowed by HTTP2 proxies. We recommend upgrading beyond the commit in  https://github.com/grpc/grpc/pull/32309 https://www.google.com/url

CVSS 3.x

Source Score Severity Vector Exploitability Impact
cve-coordination@google.com 5.3 MEDIUM CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L 3.9 1.4

Products Affected

Vendor Product Version
fedoraproject fedora 37
fedoraproject fedora 38
grpc grpc *
CVE-2023-33953

gRPC contains a vulnerability that allows hpack table accounting errors could lead to unwanted disconnects between clients and servers in exceptional cases/ Three vectors were found that allow the following DOS attacks: - Unbounded memory buffering in the HPACK parser - Unbounded CPU consumption in the HPACK parser The unbounded CPU consumption is down to a copy that occurred per-input-block in the parser, and because that could be unbounded due to the memory copy bug we end up with an O(n^2) parsing loop, with n selected by the client. The unbounded memory buffering bugs: - The header size limit check was behind the string reading code, so we needed to first buffer up to a 4 gigabyte string before rejecting it as longer than 8 or 16kb. - HPACK varints have an encoding quirk whereby an infinite number of 0’s can be added at the start of an integer. gRPC’s hpack parser needed to read all of them before concluding a parse. - gRPC’s metadata overflow check was performed per frame, so that the following sequence of frames could cause infinite buffering: HEADERS: containing a: 1 CONTINUATION: containing a: 2 CONTINUATION: containing a: 3 etc…

CVSS 3.x

Source Score Severity Vector Exploitability Impact
cve-coordination@google.com 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H 3.9 3.6

Products Affected

Vendor Product Version
grpc grpc *
CVE-2023-44487

The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H 3.9 3.6

Products Affected

Vendor Product Version
redhat openshift_service_mesh 2.0
f5 big-ip_link_controller *
cisco ios_xr *
redhat openshift_distributed_tracing -
amazon opensearch_data_prepper *
jenkins jenkins *
apple swiftnio_http/2 *
f5 big-ip_ddos_hybrid_defender 17.1.0
redhat logging_subsystem_for_red_hat_openshift -
microsoft windows_10_1809 *
traefik traefik 3.0.0
dena h2o *
kazu-yamamoto http2 *
linkerd linkerd 2.13.1
f5 big-ip_local_traffic_manager *
redhat jboss_a-mq 7
f5 big-ip_application_visibility_and_reporting *
cisco crosswork_data_gateway *
cisco unified_contact_center_enterprise -
redhat advanced_cluster_security 3.0
netty netty *
f5 big-ip_advanced_web_application_firewall 17.1.0
redhat openshift_pipelines -
cisco firepower_threat_defense *
redhat network_observability_operator -
cisco nx-os *
redhat openshift_api_for_data_protection -
cisco prime_network_registrar *
f5 big-ip_webaccelerator *
grpc grpc 1.57.0
redhat enterprise_linux 9.0
fedoraproject fedora 38
netapp astra_control_center -
netapp oncommand_insight -
apache tomcat *
f5 big-ip_analytics *
f5 big-ip_carrier-grade_nat 17.1.0
microsoft azure_kubernetes_service *
redhat certification_for_red_hat_enterprise_linux 9.0
redhat service_telemetry_framework 1.5
redhat jboss_fuse 7.0.0
redhat integration_camel_for_spring_boot -
f5 nginx_plus *
akka http_server *
redhat openstack_platform 17.1
cisco data_center_network_manager -
f5 big-ip_application_security_manager 17.1.0
microsoft windows_10_21h2 *
f5 big-ip_policy_enforcement_manager *
microsoft asp.net_core *
f5 big-ip_analytics 17.1.0
linkerd linkerd 2.13.0
redhat service_interconnect 1.0
f5 big-ip_application_security_manager *
redhat self_node_remediation_operator -
cisco secure_dynamic_attributes_connector *
cisco secure_malware_analytics *
redhat satellite 6.0
redhat build_of_quarkus -
f5 nginx_ingress_controller *
cisco ultra_cloud_core_-_serving_gateway_function *
f5 big-ip_application_visibility_and_reporting 17.1.0
redhat jboss_core_services -
redhat build_of_optaplanner 8.0
f5 big-ip_webaccelerator 17.1.0
redhat jboss_fuse 6.0.0
f5 big-ip_fraud_protection_service *
microsoft windows_server_2022 -
redhat openshift_data_science -
redhat openshift_gitops -
envoyproxy envoy 1.24.10
f5 big-ip_link_controller 17.1.0
f5 big-ip_ssl_orchestrator 17.1.0
linkerd linkerd 2.14.0
redhat integration_camel_k -
linkerd linkerd *
f5 big-ip_global_traffic_manager 17.1.0
redhat enterprise_linux 6.0
apache traffic_server *
redhat advanced_cluster_management_for_kubernetes 2.0
nodejs node.js *
apache apisix *
f5 big-ip_ddos_hybrid_defender *
linkerd linkerd 2.14.1
nghttp2 nghttp2 *
redhat node_maintenance_operator -
caddyserver caddy *
redhat ceph_storage 5.0
redhat openshift -
debian debian_linux 12.0
cisco unified_contact_center_management_portal -
microsoft windows_10_22h2 *
cisco ultra_cloud_core_-_policy_control_function *
f5 big-ip_application_acceleration_manager *
apache solr *
f5 nginx_plus r30
redhat openshift_serverless -
f5 big-ip_domain_name_system 17.1.0
debian debian_linux 11.0
projectcontour contour *
redhat openshift_dev_spaces -
f5 big-ip_next 20.0.1
cisco crosswork_data_gateway 5.0
cisco ultra_cloud_core_-_session_management_function *
f5 big-ip_websafe 17.1.0
redhat enterprise_linux 8.0
f5 big-ip_access_policy_manager 17.1.0
redhat quay 3.0.0
redhat openshift_secondary_scheduler_operator -
redhat jboss_data_grid 7.0.0
redhat jboss_enterprise_application_platform 7.0.0
cisco secure_web_appliance_firmware *
redhat advanced_cluster_security 4.0
eclipse jetty *
microsoft cbl-mariner *
cisco fog_director *
f5 big-ip_advanced_web_application_firewall *
ietf http 2.0
cisco prime_infrastructure *
cisco business_process_automation *
redhat cert-manager_operator_for_red_hat_openshift -
redhat migration_toolkit_for_containers -
cisco unified_contact_center_domain_manager -
redhat support_for_spring_boot -
redhat cryostat 2.0
redhat openstack_platform 16.2
microsoft windows_server_2019 -
redhat node_healthcheck_operator -
envoyproxy envoy 1.26.4
redhat jboss_a-mq_streams -
cisco unified_attendant_console_advanced -
cisco ios_xe *
cisco expressway *
redhat certification_for_red_hat_enterprise_linux 8.0
cisco connected_mobile_experiences *
f5 big-ip_domain_name_system *
microsoft windows_11_22h2 *
istio istio *
microsoft windows_server_2016 -
f5 big-ip_websafe *
microsoft visual_studio_2022 *
redhat openshift_container_platform 4.0
redhat single_sign-on 7.0
f5 nginx_plus r29
redhat openshift_sandboxed_containers -
redhat migration_toolkit_for_virtualization -
f5 big-ip_ssl_orchestrator *
redhat openshift_virtualization 4
redhat 3scale_api_management_platform 2.0
redhat migration_toolkit_for_applications 6.0
redhat openshift_container_platform_assisted_installer -
f5 big-ip_advanced_firewall_manager *
microsoft windows_11_21h2 *
facebook proxygen *
f5 nginx *
redhat run_once_duration_override_operator -
f5 big-ip_carrier-grade_nat *
envoyproxy envoy 1.27.0
f5 big-ip_fraud_protection_service 17.1.0
redhat decision_manager 7.0
cisco iot_field_network_director *
cisco prime_cable_provisioning *
golang networking *
redhat fence_agents_remediation_operator -
redhat openshift_developer_tools_and_services -
redhat cost_management -
redhat jboss_enterprise_application_platform 6.0.0
f5 big-ip_next_service_proxy_for_kubernetes *
f5 big-ip_access_policy_manager *
f5 big-ip_advanced_firewall_manager 17.1.0
redhat machine_deletion_remediation_operator -
f5 big-ip_global_traffic_manager *
redhat ansible_automation_platform 2.0
f5 big-ip_application_acceleration_manager 17.1.0
microsoft windows_10_1607 *
cisco prime_access_registrar *
redhat openstack_platform 16.1
cisco telepresence_video_communication_server *
openresty openresty *
cisco unified_contact_center_enterprise_-_live_data_server *
microsoft .net *
linecorp armeria *
cisco crosswork_situation_manager -
debian debian_linux 10.0
redhat integration_service_registry -
f5 big-ip_policy_enforcement_manager 17.1.0
golang go *
grpc grpc *
cisco crosswork_zero_touch_provisioning *
fedoraproject fedora 37
f5 big-ip_local_traffic_manager 17.1.0
cisco ultra_cloud_core_-_policy_control_function 2024.01.0
redhat process_automation 7.0
redhat web_terminal -
traefik traefik *
varnish_cache_project varnish_cache *
golang http2 *
cisco enterprise_chat_and_email -
apache tomcat 11.0.0
konghq kong_gateway *
envoyproxy envoy 1.25.9
CVE-2023-4785

Lack of error handling in the TCP server in Google's gRPC starting version 1.23 on posix-compatible platforms (ex. Linux) allows an attacker to cause a denial of service by initiating a significant number of connections with the server. Note that gRPC C++ Python, and Ruby are affected, but gRPC Java, and Go are NOT affected.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H 3.9 3.6
cve-coordination@google.com 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H 3.9 3.6

Products Affected

Vendor Product Version
grpc grpc 1.56.0
grpc grpc *
CVE-2024-11407

There exists a denial of service through Data corruption in gRPC-C++ - gRPC-C++ servers with transmit zero copy enabled through the channel arg GRPC_ARG_TCP_TX_ZEROCOPY_ENABLED can experience data corruption issues. The data sent by the application may be corrupted before transmission over the network thus leading the receiver to receive an incorrect set of bytes causing RPC requests to fail. We recommend upgrading past commit e9046b2bbebc0cb7f5dc42008f807f6c7e98e791

Products Affected

Vendor Product Version
grpc grpc *
CVE-2024-7246

It's possible for a gRPC client communicating with a HTTP/2 proxy to poison the HPACK table between the proxy and the backend such that other clients see failed requests. It's also possible to use this vulnerability to leak other clients HTTP header keys, but not values. This occurs because the error status for a misencoded header is not cleared between header reads, resulting in subsequent (incrementally indexed) added headers in the first request being poisoned until cleared from the HPACK table. Please update to a fixed version of gRPC as soon as possible. This bug has been fixed in 1.58.3, 1.59.5, 1.60.2, 1.61.3, 1.62.3, 1.63.2, 1.64.3, 1.65.4.

Products Affected

Vendor Product Version
grpc grpc *