gRPC contains a vulnerability whereby a client can cause a termination of connection between a HTTP2 proxy and a gRPC server: a base64 encoding error for `-bin` suffixed headers will result in a disconnection by the gRPC server, but is typically allowed by HTTP2 proxies. We recommend upgrading beyond the commit in https://github.com/grpc/grpc/pull/32309 https://www.google.com/url
CVSS Details
- CVSS 3.1 Base Score: 5.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | No solution exists | May 15, 2025 | Jun 9, 2023 |
| Suse | — | Upgrade grpc-develUpgrade abseil-cpp-develUpgrade libprotoc25_1_0Upgrade python311-grpcioUpgrade libgrpc37Upgrade libgrpc1_60Upgrade libprotoc25_1_0-32bitUpgrade protobuf-javaUpgrade grpc-sourceUpgrade libre2-11-32bitUpgrade libre2-11Upgrade libprotobuf-lite25_1_0Upgrade protobuf-develUpgrade python311-abseilUpgrade libupb37Upgrade libabsl2308_0_0Upgrade libprotobuf25_1_0-32bitUpgrade python311-protobufUpgrade opencensus-proto-sourceUpgrade upb-develUpgrade re2-develUpgrade libprotobuf-lite25_1_0-32bitUpgrade libprotobuf25_1_0Upgrade libgrpc++1_60Upgrade libabsl2308_0_0-32bit | Feb 22, 2024 | Jun 9, 2023 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Jun 9, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub