Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4g9c-3x4p-mfpp

Опубликовано: 28 апр. 2026
Источник: github
Github: Прошло ревью
CVSS3: 4.2

Описание

Spring gRPC SecurityContext leaks across requests upon authorization failure

When an authenticated user is denied access to a gRPC method, their authenticated identity remains bound to the gRPC worker thread and can be inherited by a subsequent unauthenticated request on the same thread. This may allow the subsequent user to gain escalated permissions.

Affected versions: Spring gRPC: 1.0.0 - 1.0.2 (fixed in 1.0.3). Older, unsupported versions are also affected.

Пакеты

Наименование

org.springframework.grpc:spring-grpc

maven
Затронутые версииВерсия исправления

< 1.0.3

1.0.3

EPSS

Процентиль: 7%
0.00171
Низкий

4.2 Medium

CVSS3

Дефекты

CWE-653

Связанные уязвимости

CVSS3: 4.2
nvd
5 месяцев назад

When an authenticated user is denied access to a gRPC method, their authenticated identity remains bound to the gRPC worker thread and can be inherited by a subsequent unauthenticated request on the same thread. This may allow the subsequent user to gain escalated permissions. Affected versions: Spring gRPC: 1.0.0 - 1.0.2 (fixed in 1.0.3). Older, unsupported versions are also affected.

EPSS

Процентиль: 7%
0.00171
Низкий

4.2 Medium

CVSS3

Дефекты

CWE-653