Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-4785

Опубликовано: 14 сент. 2023
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

Lack of error handling in the TCP server in Google's gRPC starting version 1.23 on posix-compatible platforms (ex. Linux) allows an attacker to cause a denial of service by initiating a significant number of connections with the server. Note that gRPC C++ Python, and Ruby are affected, but gRPC Java, and Go are NOT affected.

A flaw was found in gRPC. Lack of error handling in the TCP server in Google's gRPC, starting in version 1.23 on POSIX-compatible platforms (for example, Linux), allows an attacker to cause a denial of service by initiating a significant number of connections with the server. Note that gRPC C++, Python, and Ruby are affected, but gRPC Java and Go are NOT affected.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift Container Platform 4grpcNot affected
Red Hat OpenShift Container Platform 4openshift4/ose-kuryr-cni-rhel8Not affected
Red Hat OpenShift Container Platform 4openshift4/ose-kuryr-controller-rhel8Not affected
Red Hat Satellite 6.14 for RHEL 8rubygem-grpcFixedRHSA-2024:079713.02.2024

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-248
https://bugzilla.redhat.com/show_bug.cgi?id=2239017gRPC: file descriptor exhaustion leads to denial of service

EPSS

Процентиль: 49%
0.00666
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 3 года назад

Lack of error handling in the TCP server in Google's gRPC starting version 1.23 on posix-compatible platforms (ex. Linux) allows an attacker to cause a denial of service by initiating a significant number of connections with the server. Note that gRPC C++ Python, and Ruby are affected, but gRPC Java, and Go are NOT affected.

CVSS3: 7.5
nvd
почти 3 года назад

Lack of error handling in the TCP server in Google's gRPC starting version 1.23 on posix-compatible platforms (ex. Linux) allows an attacker to cause a denial of service by initiating a significant number of connections with the server. Note that gRPC C++ Python, and Ruby are affected, but gRPC Java, and Go are NOT affected.

CVSS3: 7.5
msrc
6 месяцев назад

Denial of Service in gRPC Core

CVSS3: 7.5
debian
почти 3 года назад

Lack of error handling in the TCP server in Google's gRPC starting ver ...

CVSS3: 7.5
github
почти 3 года назад

Denial of Service Vulnerability in gRPC TCP Server (Posix-compatible platforms)

EPSS

Процентиль: 49%
0.00666
Низкий

7.5 High

CVSS3