Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-47609

Опубликовано: 01 окт. 2024
Источник: nvd
EPSS Низкий

Описание

Tonic is a native gRPC client & server implementation with async/await support. When using tonic::transport::Server there is a remote DoS attack that can cause the server to exit cleanly on accepting a TCP/TLS stream. This can be triggered by causing the accept call to error out with errors that were not covered correctly causing the accept loop to exit. Upgrading to tonic 0.12.3 and above contains the fix.

EPSS

Процентиль: 46%
0.00622
Низкий

Дефекты

CWE-755

Связанные уязвимости

ubuntu
почти 2 года назад

Tonic is a native gRPC client & server implementation with async/await support. When using tonic::transport::Server there is a remote DoS attack that can cause the server to exit cleanly on accepting a TCP/TLS stream. This can be triggered by causing the accept call to error out with errors that were not covered correctly causing the accept loop to exit. Upgrading to tonic 0.12.3 and above contains the fix.

CVSS3: 3.7
redhat
почти 2 года назад

Tonic is a native gRPC client & server implementation with async/await support. When using tonic::transport::Server there is a remote DoS attack that can cause the server to exit cleanly on accepting a TCP/TLS stream. This can be triggered by causing the accept call to error out with errors that were not covered correctly causing the accept loop to exit. Upgrading to tonic 0.12.3 and above contains the fix.

debian
почти 2 года назад

Tonic is a native gRPC client & server implementation with async/await ...

CVSS3: 5.3
github
почти 2 года назад

Tonic has remotely exploitable denial of service vulnerability

EPSS

Процентиль: 46%
0.00622
Низкий

Дефекты

CWE-755