Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-37w2-q6vh-45v6

Опубликовано: 28 апр. 2026
Источник: github
Github: Прошло ревью
CVSS3: 3.7

Описание

Spring gRPC AuthenticationException messages are reflected to remote client

The raw message of every server-side AuthenticationException is returned to the unauthenticated remote caller in the gRPC status description. This allows an attacker to obtain information about the authentication failure, which may be useful for further attacks.

Affected versions: Spring gRPC: 1.0.0 - 1.0.2 (fixed in 1.0.3). Older, unsupported versions are also affected.

Пакеты

Наименование

org.springframework.grpc:spring-grpc

maven
Затронутые версииВерсия исправления

< 1.0.3

1.0.3

EPSS

Процентиль: 10%
0.002
Низкий

3.7 Low

CVSS3

Дефекты

CWE-209

Связанные уязвимости

CVSS3: 3.7
nvd
4 месяца назад

The raw message of every server-side AuthenticationException is returned to the unauthenticated remote caller in the gRPC status description. This allows an attacker to obtain information about the authentication failure, which may be useful for further attacks. Affected versions: Spring gRPC: 1.0.0 - 1.0.2 (fixed in 1.0.3). Older, unsupported versions are also affected.

EPSS

Процентиль: 10%
0.002
Низкий

3.7 Low

CVSS3

Дефекты

CWE-209