Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g76f-gjfx-4rpr

Опубликовано: 04 сент. 2024
Источник: github
Github: Прошло ревью
CVSS4: 6.9
CVSS3: 5.8

Описание

Vertx gRPC server does not limit the maximum message size

In Eclipse Vert.x version 4.3.0 to 4.5.9, the gRPC server does not limit the maximum length of message payload (Maven GAV: io.vertx:vertx-grpc-server and io.vertx:vertx-grpc-client). 

This is fixed in the 4.5.10 version. 

Note this does not affect the Vert.x gRPC server based grpc-java and Netty libraries (Maven GAV: io.vertx:vertx-grpc)

Пакеты

Наименование

io.vertx:vertx-grpc-server

maven
Затронутые версииВерсия исправления

>= 4.3.0, < 4.5.10

4.5.10

Наименование

io.vertx:vertx-grpc-client

maven
Затронутые версииВерсия исправления

>= 4.3.0, < 4.5.10

4.5.10

EPSS

Процентиль: 45%
0.0058
Низкий

6.9 Medium

CVSS4

5.8 Medium

CVSS3

Дефекты

CWE-770

Связанные уязвимости

CVSS3: 7.5
redhat
почти 2 года назад

In Eclipse Vert.x version 4.3.0 to 4.5.9, the gRPC server does not limit the maximum length of message payload (Maven GAV: io.vertx:vertx-grpc-server and io.vertx:vertx-grpc-client).  This is fixed in the 4.5.10 version.  Note this does not affect the Vert.x gRPC server based grpc-java and Netty libraries (Maven GAV: io.vertx:vertx-grpc)

CVSS3: 7.5
nvd
почти 2 года назад

In Eclipse Vert.x version 4.3.0 to 4.5.9, the gRPC server does not limit the maximum length of message payload (Maven GAV: io.vertx:vertx-grpc-server and io.vertx:vertx-grpc-client).  This is fixed in the 4.5.10 version.  Note this does not affect the Vert.x gRPC server based grpc-java and Netty libraries (Maven GAV: io.vertx:vertx-grpc)

EPSS

Процентиль: 45%
0.0058
Низкий

6.9 Medium

CVSS4

5.8 Medium

CVSS3

Дефекты

CWE-770