Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-4785

Опубликовано: 13 сент. 2023
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

Lack of error handling in the TCP server in Google's gRPC starting version 1.23 on posix-compatible platforms (ex. Linux) allows an attacker to cause a denial of service by initiating a significant number of connections with the server. Note that gRPC C++ Python, and Ruby are affected, but gRPC Java, and Go are NOT affected.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:grpc:grpc:*:*:*:*:*:-:*:*
Версия от 1.23.0 (включая) до 1.53.2 (исключая)
cpe:2.3:a:grpc:grpc:*:*:*:*:*:-:*:*
Версия от 1.54.0 (включая) до 1.54.3 (исключая)
cpe:2.3:a:grpc:grpc:*:*:*:*:*:-:*:*
Версия от 1.55.0 (включая) до 1.55.3 (исключая)
cpe:2.3:a:grpc:grpc:1.56.0:*:*:*:*:-:*:*

EPSS

Процентиль: 4%
0.00018
Низкий

7.5 High

CVSS3

Дефекты

CWE-248
NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 2 лет назад

Lack of error handling in the TCP server in Google's gRPC starting version 1.23 on posix-compatible platforms (ex. Linux) allows an attacker to cause a denial of service by initiating a significant number of connections with the server. Note that gRPC C++ Python, and Ruby are affected, but gRPC Java, and Go are NOT affected.

CVSS3: 7.5
redhat
больше 2 лет назад

Lack of error handling in the TCP server in Google's gRPC starting version 1.23 on posix-compatible platforms (ex. Linux) allows an attacker to cause a denial of service by initiating a significant number of connections with the server. Note that gRPC C++ Python, and Ruby are affected, but gRPC Java, and Go are NOT affected. 

CVSS3: 7.5
msrc
больше 1 года назад

Описание отсутствует

CVSS3: 7.5
debian
больше 2 лет назад

Lack of error handling in the TCP server in Google's gRPC starting ver ...

CVSS3: 7.5
github
больше 2 лет назад

Denial of Service Vulnerability in gRPC TCP Server (Posix-compatible platforms)

EPSS

Процентиль: 4%
0.00018
Низкий

7.5 High

CVSS3

Дефекты

CWE-248
NVD-CWE-noinfo