Skip to content

gRPC contains a vulnerability CVE-2023-32732 #3038

@DirkRichter

Description

@DirkRichter

Problem description

gRPC contains a vulnerability whereby a client can cause a termination of connection between a HTTP2 proxy and a gRPC server: a base64 encoding error for -bin suffixed headers will result in a disconnection by the gRPC server, but is typically allowed by HTTP2 proxies. We recommend upgrading to v1.53.0 beyond the commit in grpc/grpc#32309

https://nvd.nist.gov/vuln/detail/cve-2023-32732

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions