5.3
CVSSv3

CVE-2023-32732

Published: 09/06/2023 Updated: 02/08/2023
CVSS v3 Base Score: 5.3 | Impact Score: 1.4 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

gRPC contains a vulnerability whereby a client can cause a termination of connection between a HTTP2 proxy and a gRPC server: a base64 encoding error for `-bin` suffixed headers will result in a disconnection by the gRPC server, but is typically allowed by HTTP2 proxies. We recommend upgrading beyond the commit in  github.com/grpc/grpc/pull/32309 www.google.com/url

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

grpc grpc

fedoraproject fedora 37

fedoraproject fedora 38

Vendor Advisories

Debian Bug report logs - #1059280 grpc: CVE-2023-32732 Package: src:grpc; Maintainer for src:grpc is Laszlo Boszormenyi (GCS) <gcs@debianorg>; Reported by: Moritz Mühlenhoff <jmm@inutilorg> Date: Fri, 22 Dec 2023 12:12:36 UTC Severity: important Tags: security, upstream Reply or subscribe to this bug Toggle ...
DescriptionThe MITRE CVE dictionary describes this issue as: gRPC contains a vulnerability whereby a client can cause a termination of connection between a HTTP2 proxy and a gRPC server: a base64 encoding error for `-bin` suffixed headers will result in a disconnection by the gRPC server, but is typically allowed by HTTP2 proxies We recommend upgr ...